← All Threat Actors
Threat Actor Profile

DragonForce

DFRC DragonForce Malaysia DragonForce Ransomware Cartel Slippery Scorpius Storm-0501
⚠ Critical Threat
UK High-Street Retail Campaign, Hybrid Cloud Pivot, US SMB Sector Wave
Origin Malaysia
Motivation financial gain

Target Sectors

Retail Manufacturing Healthcare Logistics Technology Critical National Infrastructure (CNI) Professional Services

Known TTPs

Double Extortion (Data Exfiltration + Encryption)
White-label RaaS/Cartel Model
BYOVD (Bring Your Own Vulnerable Driver) using truesight.sys and rentdrv2.sys to disable EDR
Cloud-native extortion (deletion of Azure backups and data without endpoint encryptors)
Vishing and advanced social engineering (via Muddled Libra partnership)
Entra ID (Azure AD) privilege escalation and persistence via malicious federated domains
C2 concealment using Backdoor.Turn via Microsoft Teams TURN relay infrastructure
Post-compromise discovery using AzureHound

External Resources

CISA Advisories ↗

Related Intelligence


LINK COPIED TO CLIPBOARD