Ransomware Group

DragonForce

Status: active • First seen 2023-1275+ known victims

DragonForce is a newer ransomware gang that uses stolen tools from the famous LockBit group. They attack factories and stores, and they are known for being very aggressive during ransom negotiations.

Overview

DragonForce is a ransomware operation that utilizes leaked LockBit builder tools to create their payloads. The group has been aggressive in their negotiations and quick to publish stolen data.

Target Industries

Manufacturing, Retail, Construction, Food & Beverage

How They Attack

  • LockBit builder tools
  • Phishing
  • Double extortion
  • VPN exploitation

Notable Victims

Coca-Cola bottler (2024), Manufacturing firms

Is your business exposed?

How to Protect Against DragonForce

  1. 1.

    Monitor for LockBit indicators of compromise

  2. 2.

    Secure VPN appliances with latest patches

  3. 3.

    Implement manufacturing OT/IT segmentation

MITRE ATT&CK Techniques

T1486, T1566, T1133, T1567

Related Groups

Lockbit

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required