Techrepublic
DragonForce Ransomware Cartel Emerges as Major Threat in Cybersecurity
Article Content
DragonForce ransomware, a RaaS operation that evolved from a pro-Palestine hacktivist group, has become a significant player in the ransomware landscape since its inception in August 2023. In March 2025, it restructured into a ransomware cartel, forming alliances with LockBit and Qilin to share resources and techniques. The group's operations have already caused substantial financial damage, notably a breach of UK retailer Marks & Spencer, which led to a profit drop from £391.4 million to £3.4 million and incurred £136 million in response costs. DragonForce employs a white-label model, allowing affiliates to operate under their own branding, making attacks harder to attribute. This model has attracted numerous affiliates, offering them an 80% cut of ransom profits. The rise of DragonForce reflects the growing trend of ransomware-as-a-service, which has enabled more amateur criminals to engage in cyber extortion. The impact of ransomware on organizations is underscored by a recent survey indicating that 90% of organizations reported operational disruptions due to such attacks.
Key Points: • DragonForce ransomware has evolved from hacktivism to a major RaaS operation. • The group formed a cartel with LockBit and Qilin to enhance its operational capabilities. • 90% of organizations report ransomware attacks have impacted their operations.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.