Skip to content

DragonForce reemerges as Conti-linked ransomware cartel, aligning with Scattered Spider ...

Industrialcyber.Co November 6, 2025

New data from Acronis Threat Research Unit (TRU) analyzed DragonForce , a Conti-derived ransomware-as-a-service active since 2023, documenting its malware, affiliate model, and links to Scattered Spider . DragonForce rebranded as a ransomware cartel, allowing affiliates to white-label payloads and create variants like Devman and Mamona/Global, while defacing rival groups to reinforce its position in the ecosystem. DragonForce and LockBit Green common lineage through the leaked Conti v3 code, leading to overlaps in routines and artifacts. Over 200 victims have been exposed on DragonForce’s leak site since late 2023, across retail, airlines, insurance, managed service providers (MSPs), and other enterprise sectors.

In early 2025, DragonForce began branding itself as a ransomware ‘cartel.’ This approach allows DragonForce to continue building its brand as one of the most notorious cybercriminal groups currently active, drawing attention from rivals and law enforcement. Through its affiliate program, DragonForce strengthened its position in the ransomware scene, attracting new partners and competing with more established RaaS operators. Additionally, this business model diversifies techniques and victims, making attribution increasingly difficult.

DragonForce employs BYOVD (bring your own vulnerable driver) attacks by using truesight[dot]sys and rentdrv2[dot]sys drivers to terminate processes.

After an article appeared in Habr, a media platform focused on technology, internet culture, and related topics, which revealed weaknesses in Akira’s encryption, DragonForce quickly reinforced its own encryptor to avoid similar problems.

“Recently, DragonForce announced a rebrand, stating that the group would now operate as a cartel. This shift in operation strategy aims to grow their presence in the ransomware scene,” Darrel Virtusio, David Catalan Alegre, Eliad Kimhy, and Santiago Pontiroli, Acronis TRU researchers wrote in a Tuesday blog post. “By offering affiliates 80 percent of profits, customizable encryptors, and infrastructure, DragonForce lowers the barrier to entry and encourages more affiliates to join the cartel. Since then, DragonForce has been more active in attacking companies globally, posting more victims compared to a year ago. Their most notable attack, publicly attributed to the group, targeted retailer Marks & Spencer in collaboration with Scattered Spider.”

Beyond ransomware groups, the post mentioned that DragonForce has also expanded its partnerships to include other cybercriminal groups within the broader underground ecosystem. Scattered Spider is one that they had partnered with after branding themselves as a ‘cartel.’

“Scattered Spider is known for partnering with other notorious RaaS operators in the past, such as BlackCat, RansomHub, and Qilin, providing initial access to the victim’s network and handing over the access for ransomware deployment,” according to the researchers. “This recent partnership drew significant attention after the attack on major U.K. retailer Marks & Spencer, which researchers attribute to Scattered Spider–DragonForce operations. Though not confirmed, this incident fits the timeline of DragonForce’s rebrand just a month before, showing that Scattered Spider was quick to leverage DragonForce in its operations.”

DragonForce is a RaaS group that first appeared in 2023 and was initially associated with the hacktivist group DragonForce Malaysia, though concrete evidence linking the two is still limited. Ever since DragonForce entered the ransomware scene, they have been actively recruiting partners on underground forums for their operation. The group started using the leaked LockBit 3.0 builder to develop its encryptors, then later adopted a customized Conti v3 code.

Among DragonForce’s partners is Scattered Spider, an initial access broker known for collaborating with multiple ransomware operations. Scattered Spider, a financially driven actor known for phishing, SIM swapping, and MFA bypass, partnered with operators tied to the DragonForce ransomware-as-a-service model. This collaboration evolved into broader overlaps with LAPSUS$ and ShinyHunters, forming what researchers dubbed the ‘Scattered LAPSUS$ Hunters’ within the ‘Hacker Com’ ecosystem.

“While the cartelization of cybercriminal groups is not new, it has gained momentum in recent years,” the researchers noted. “Beyond DragonForce, groups like Scattered Spider, LAPSUS$, and ShinyHunters have formed collectives such as Scattered LAPSUS$ Hunters, reportedly behind several high-profile breaches involving Salesforce customers. This shift from competition to collaboration marks a growing risk for organizations worldwide.”

Detailing how Scattered Spider enables DragonForce ransomware deployments, the researchers mentioned that the intrusion typically involves Scattered Spider identifying their target victims by performing reconnaissance on the organization’s employees to create a persona and pretext. “They gather victim information such as name, role, and other general information through social media and open-source intelligence methods.”

Furthermore, the group employs sophisticated social engineering techniques such as spear-phishing emails and voice phishing (vishing) to obtain and/or reset victim credentials and bypass MFA through convincing lures, multifactor authentication fatigue, or SIM swaps. Once successful, Scattered Spider logs in as the targeted user and enrolls their own device for access.

“After the initial compromise, Scattered Spider deploys remote monitoring and management ( RMM ) tools or tunneling services to establish persistence,” the post added. “The group has been seen using ScreenConnect, AnyDesk, TeamViewer, Splashtop, and similar utilities. Once inside the environment, Scattered Spider conducts extensive discovery, focusing on SharePoint, credential stores, VMware vCenter infrastructure, backup systems , and documentation related to VPN setup and access. The group also enumerates Active Directory (AD) to map the network.”

Recently, Scattered Spider has been using AWS Systems Manager Inventory to identify additional targets for lateral movement. They use extract, transform and load (ETL) tools to aggregate collected data into a centralized repository, which is then exfiltrated to attacker-controlled MEGA or Amazon S3 storage. Finally, Scattered Spider deploys the DragonForce ransomware payload and encrypts files across Windows, Linux, and ESXi systems.

The Acronis team also highlighted that one of the clearest indications of DragonForce’s growing presence in the ransomware landscape lies in its growing number of affiliates, particularly those moving from one ransomware group to another. “Recently, we have found samples of Devman ransomware built using DragonForce’s builder. This sample has ‘[dot]devman’ as the encrypted file extension in its configuration, but other functionalities like the icon, wallpaper, and ransom note are all from DragonForce.”

“The connection between DragonForce and Devman can also be seen in the similarities of their ransom note structure. Devman, which initially began deploying a Mamona-based variant around May 2025, used a ransom note format that closely mirrors DragonForce’s LockBit-based variant, which was first seen in the wild around mid-2023,” the post added. “This resemblance may not be a coincidence. The time gap between both samples and the builder used on both samples suggests that Devman may have been an early DragonForce affiliate experimenting to create its own branding while continuing to rely on DragonForce’s infrastructure and tools.”

In conclusion, the Acronis team identified that, similar to ransomware such as Akira, Royal, and Black Basta, “DragonForce used the Conti leaked source code to forge a dark successor crafted to carry its own mark. While other groups made some changes to the code to give it a different spin, DragonForce kept all functionality unchanged, only adding an encrypted configuration in the executable to get rid of command-line arguments that were used in the original Conti code.”

They added that by fixing Akira’s encryption flaws and strengthening its cipher, this threat actor has focused on steadily expanding its victim list and recruiting new affiliates, proving itself as a significant and persistent threat.

Extracted Entities