Sentrix

Actor · Cartel · since 2023

DragonForce: the cartel that rents out its infrastructure

Profile of DragonForce, which moved from RaaS to cartel in March 2025: white-label brands for affiliates, help desk social engineering, UK retail attacks.

Model
Cartel · since 2023-08
Aliases
DragonForce Ransomware Cartel, RansomBay
Ways in
Email phishing · Credential stuffing against RDP and VPN · Password reset obtained from the help desk · Known vulnerabilities (Ivanti, Log4Shell)
Targets
Retail · Manufacturing · Real estate · Transportation

By Sentrix · Published 2026-09-20

Who they are

DragonForce emerged in August 2023 as a conventional ransomware-as-a-service scheme, according to Sophos. SentinelOne adds that the group first presented itself as a pro-Palestine hacktivist operation before turning to extortion, and that its early payloads were based entirely on the leaked LockBit 3.0 (LockBit Black) builder, later replaced by an in-house variant with roots in the Conti v3 codebase.

The turning point came on March 19, 2025: in an underground forum post, DragonForce rebranded itself as a "cartel" and announced a distributed model in which each affiliate can create its own brand, according to Sophos. The cartel supplies the administration and negotiation panels, the encryption tools, storage for stolen files and a Tor-based leak site; the affiliate brings the access and keeps the larger share. Group-IB had already documented, on June 26, 2024, the public launch of the affiliate program with the promise of 80% of revenue, followed by a requirement added on July 4, 2024: target organizations with revenue above five million US dollars.

The result is a structure in which the name on the ransom note no longer says who attacked. The cartel rents the infrastructure; very different teams use it.

How they get in

SentinelOne describes three entry routes: email phishing, exploitation of known vulnerabilities (Log4Shell CVE-2021-44228, Ivanti CVE-2023-46805 and CVE-2024-21887) and stolen or leaked credentials, with heavy credential stuffing against RDP and attacks on VPN weaknesses. Group-IB notes, in one intrusion it analyzed, suspicious logins from three different IP addresses using valid domain accounts.

The 2025 attacks on UK retail brought a fourth route into view: the NCSC points to speculation about social engineering of IT help desks to obtain credential resets. No software vulnerability is needed when a support agent resets an administrator's password on the strength of a phone call.

What they have done

  • June 2024: affiliate program opens. Group-IB dates the public announcement to June 26, 2024 and counts, between August 2023 and August 2024, 82 victims on the leak site, led by manufacturing, real estate and transportation, with the United States accounting for 43 of them.
  • March 2025: the cartel. Sophos records the March 19, 2025 post and counts 136 victims on the leak site as of March 24, 2025.
  • April and May 2025: Marks & Spencer, Co-op and Harrods. SentinelOne documents a series of coordinated attacks on UK retailers attributed to DragonForce. The NCSC published sector-wide recommendations on May 4, 2025 without naming the victims or confirming a link between the incidents.

What stops them

  1. Multi-factor authentication everywhere, with no exception for administrators. The NCSC calls for comprehensive deployment of 2-step verification. ISO 27001:2022, 5.17 and 8.5; SOC 2, CC6.1.
  2. Help desk reset procedure. Verify the caller's identity through an independent channel before any password or MFA factor change, especially for privileged accounts, as the NCSC recommends. ISO 27001:2022, 5.16 and 5.18.
  3. Privileged account review. The NCSC asks for specific attention to Domain Admin, Enterprise Admin and Cloud Admin accounts. A service account or a former supplier holding those rights is an affiliate's ideal target. ISO 27001:2022, 8.2; SOC 2, CC6.3.
  4. Detection of atypical logins. Alert on logins from VPN services in residential ranges and on "risky logins" in Entra ID Protection, per the NCSC. SOC 2, CC7.2; ISO 27001:2022, 8.16.
  5. Patching of exposed gateways. The Ivanti and Log4Shell CVEs cited by SentinelOne all have fixes; a fast patch cycle for edge devices closes this door. ISO 27001:2022, 8.8; SOC 2, CC7.1.
  6. Offline backups and restoration drills. A cartel that makes its encryptor and leak site available to multiple brands leaves little room for negotiation; restoration must be tested, not assumed. ISO 27001:2022, 8.13; SOC 2, A1.2.

Sources

Frequently asked questions

What is a ransomware cartel?
An operator that rents out its complete infrastructure, administration and negotiation panels, encryptor, storage and leak site, to affiliates who can publish under their own brand. Sophos describes this model, announced by DragonForce on March 19, 2025. The consequence for defenders: the name on the ransom note no longer tells you anything about the attacker's techniques, which vary from one affiliate to the next.
Were the 2025 attacks on UK retailers the work of DragonForce?
SentinelOne attributes the series of attacks on Marks & Spencer, Co-op and Harrods to DragonForce, whose infrastructure was used. The NCSC, for its part, neither named the victims nor confirmed a link between the incidents in its May 4, 2025 recommendations, while noting speculation about help desk social engineering. Caution is warranted on attribution, not on the lessons to draw.
What is the most cost-effective control against this cartel?
The help desk password reset procedure, combined with comprehensive MFA. The NCSC asks organizations to review how the help desk authenticates a staff member before resetting a password, especially for privileged accounts. It is a procedure, not a product; it can be put in place within days and closes the entry route most discussed in 2025.

Let's talk about your compliance program.

Last updated: 2026-09-20