Mamona Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
November 4, 2025
Last Seen
February 10, 2026

Mamona is a ransomware malware family associated with the DragonForce/Conti-linked ransomware ecosystem, which has recently reemerged and aligned with Scattered Spider.

Overview

Mamona is a ransomware malware family associated with the DragonForce/Conti-linked ransomware ecosystem, which has recently reemerged and aligned with Scattered Spider. It participates in double-extortion operations, encrypting victim data and exfiltrating information to pressure payment, signaling the continued monetization and evolution of the Conti affiliate network.

Related Threat Clusters

  • DragonForce Emerges as Conti-Linked Ransomware Cartel

    DragonForce, a new ransomware operation derived from Conti's leaked source code, has emerged with a cartel-like structure. The group retains Conti's core encryption and network-spreading capabilities while recruiting…

    2 articles · Updated November 6, 2025
  • DragonForce Claims Breach of HanseMerkur and Mobilelink USA

    The DragonForce ransomware gang has claimed responsibility for the breach of major German insurer HanseMerkur, alleging the theft of nearly 97 GB of internal corporate data, including sensitive financial documents.…

    2 articles · Updated February 5, 2026
  • Medusa and DragonForce Ransomware Exploit RMM Tools in 2025 UK Attacks

    In 2025, ransomware groups Medusa and DragonForce targeted UK organizations by exploiting three critical vulnerabilities in the SimpleHelp Remote Monitoring and Management platform. These vulnerabilities…

    9 articles · Updated November 11, 2025
  • Phorpiex Phishing Campaign Uses Weaponized Windows Shortcuts

    A phishing campaign leveraging the Phorpiex malware has been identified, utilizing weaponized Windows shortcut files to deliver Global Group ransomware. The campaign, which began in late 2024 and continues into 2026,…

    9 articles · Updated February 10, 2026

Recent Intelligence Reports

  • Phorpiex malware delivers global group ransomware via phishing — Scworld · February 10, 2026
  • DragonForce ransomware claims Mobilelink USA breach — Scworld · December 4, 2025
  • DragonForce reemerges as Conti-linked ransomware cartel, aligning with Scattered Spider ... — Industrialcyber.Co · November 6, 2025
  • DragonForce Cartel Emerges as Conti — Infosecurity-Magazine · November 4, 2025

CVSS v3.1 Breakdown