A new and particularly dangerous ransomware, known as DragonForce, has emerged as one of the most serious threats to organizations worldwide since its first appearance in late 2023. Experts warn that it is a highly sophisticated malware campaign that targets critical business infrastructure across multiple sectors, causing massive financial losses and data breach risks.

DragonForce is not limited to just encrypting files, but also stealing data and using a full-blown extortion strategy.
DragonForce: The new generation of ransomware-as-a-service
The team behind DragonForce operates under the model ransomware-as-a-service (RaaS), offering its malware as a “service” to cybercriminal partners. This way, even attackers without deep technical knowledge can launch devastating attacks using ready-made tools, infrastructure, and instructions.
See also: DEAD#VAX campaign deploys AsyncRAT via Phishing VHD files
This model has turned ransomware into an entire criminal "industry", where creators share the profits from the ransom with the partners who carry out the attacks.
Double blackmail strategy: Encryption and data leakage
One of the most worrying features of DragonForce is its use of double blackmail. The attackers don't just lock down an organization's data through encryption, they also copy and steal sensitive information.
then threaten to publish the stolen data on dark web leak sites if the ransom is not paid. This method dramatically increases the pressure on victims, as even if backups are available, the threat of a leak remains a powerful blackmail weapon.

The sectors that are in the spotlight
According to LevelBlue analyses , DragonForce has focused particularly on critical business areas such as :
- manufacturing
- business services
- technology
- constructions
The countries with the highest concentration of attacks include the United States, the United Kingdom, Germany, Australia, and Italy, indicating that the group primarily targets developed economies with large operational infrastructures.
Multi-platform threat with huge reach
What makes DragonForce even more dangerous is its ability to affect multiple operating environments. The ransomware can attack:
- Windows
- Linux
- VMware ESXi
- BSD
- NAS systems
This gives attackers enormous flexibility, as they can target both corporate servers and virtualization infrastructures widely used in data centers.
See also: Abuse of Google & Microsoft to target corporate users
Advanced encryption techniques and "test attacks"
DragonForce supports various encryption methods, such as full, partial, or header encryption. It also provides delayed launch capabilities so that attacks can be triggered at specific times, such as outside of IT team hours.
One particularly worrying feature is the “test run” capability, where partners can simulate the attack without actual encryption, first testing the effectiveness of the penetration.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Methods of contamination and destructive recovery actions
During execution, the ransomware performs network reconnaissance, scanning SMB ports to locate vulnerable systems. It also leverages code linked to leaks Conti ransomware, demonstrating that the groups are reusing older tools.
Particularly critical is that DragonForce deletes volume shadow copies via Windows Management Instrumentation Command-line (WMIC) commands, preventing victims from restoring data from snapshots.
See also: Google Play: Malicious app with 50,000 downloads distributed by Anatsa malware
How can organizations protect themselves?
Experts recommend strong defensive measures, such as:
- multi-factor authentication application
- strict security update management
- regular offline backups
- advanced EDR and anti-ransomware tools
- application control to prevent unauthorized execution
DragonForce is a reminder that ransomware threats are constantly evolving and require constant vigilance.
