Active ransomware operator
← All groupsDragonforce
537 victims indexed · first seen 2 years ago · last activity 15 hours ago
At a glance
- Status
- active
- First seen
- 2 years ago
- Last activity
- 15 hours ago
- Onion sites
- 4 known endpoints
- Primary sector
- Not Found · 119 hits
About
References
8 linksExternal sources curated by the MISP threat-intel community.
- ransomlook.io/group/dragonforce
- ransomware.live/group/dragonforce
- sentinelone.com/blog/dragonforce-ransomware-gang-from-hacktivists-to-high-street-extortionists/
- barracuda.com/blog/dragonforce-ransomware-cartel-vs--everybody
- secureworks.com/blog/ransomware-groups-evolve-affiliate-models
- reuters.com/business/retail-consumer/ms-cyberattack-was-carried-out-by-dragonforce-chairman-says-2025-07-08/
- ft.com/content/22cb54ef-1611-4aef-b671-16316280e3fb
- scworld.com/brief/dragonforce-victimization-on-the-rise-report-finds
Timeline
24 monthsTop countries
Top sectors
MITRE ATT&CK
8 techniques · 7 tacticsTactics
Recent victims
Loading…
Onion infrastructure
4 known- http://3pktcrcbmssvrnwe5skburdwe2h3v6ibdnn5kbjqihsg6eu6s6b7ryqd.onion
- http://3pktcrcbmssvrnwe5skburdwe2h3v6ibdnn5kbjqihsg6eu6s6b7ryqd.onion/login
- http://z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion
- http://z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion/api/guest/blog/posts?page=1
Source
Updated 15 hours agoData on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.
