🔴 [LATEST] PARAGUAY'S MITIC SERVER DOWN FOR 24 HOURS, THEGARUDAEYE IN SPOTLIGHT    ◆    🔴 [LATEST] THEHATMAN SELLS 3.6 MILLION AZURE EMPLOYEE RECORDS FROM FORTUNE 500 COMPANIES    ◆    🔴 [LATEST] 24 HOURS OF DIGITAL BLACKOUT: THEGARUDAEYE SILENCES PARAGUAY'S CULTURE MINISTRY PORTAL IN THE NAME OF PALESTINE    ◆    🔴 [LATEST] WHERE HAS DRAGONFORCE MALAYSIA GONE? THE SILENCE OF SOUTHEAST ASIA'S PREMIER HACKTIVISTS    ◆    🔴 [LATEST] BREACHFORUMS ADMIN: HASANBROKER WAS A PREDATOR? DARK WEB FORUM WARS EXPLODE

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Global
DRAGONFORCE RANSOMWARE

/actor/dragonforce-ransomware/  ·  1 intel report

Year Established
2023
Attribution
Malaysia (Suspected)
Motivation
Financial, Hacktivism (Origins)
Modus Operandi (MO)
RaaS, LockBit/Conti-based ransomware, pivot from hacktivism to criminal ransomware operation
Primary Aliases
DragonForce Malaysia (historical), Dragon Force

DragonForce Ransomware represents an unusual evolution in the threat landscape: a group that began as a Malaysian nationalist hacktivist collective , DragonForce Malaysia , and subsequently pivoted to operating a sophisticated Ransomware-as-a-Service (RaaS) criminal enterprise. This transition from ideologically motivated hacktivism to financially motivated organised cybercrime is a documented but relatively rare phenomenon.

DragonForce Malaysia originally gained notoriety conducting #OpsPatuk and similar nationalist hacktivist campaigns targeting Israeli and Indian organisations during periods of geopolitical tension, conducting web defacement and DDoS attacks. The group's transformation into a ransomware operation marked a significant escalation in both capability and criminality, though some researchers assess the "Malaysia" connection of the RaaS arm as potential misdirection.

DragonForce Ransomware operates a RaaS model with a leak site where victim data is published following non-payment. Security researchers identified that their ransomware encryptor was initially based on leaked LockBit 3.0 and Conti source code, though the group has since developed increasingly customised tooling. They offer affiliates an 80% revenue share and provide a sophisticated affiliate panel with victim management, negotiation chat, and data publishing capabilities.

In 2024, DragonForce made headlines by announcing the formation of a ransomware "cartel" , recruiting other ransomware brands including RansomHub to operate under the DragonForce infrastructure umbrella. This cartel model, if sustained, represents a potentially significant centralisation of ransomware-as-a-service infrastructure that could complicate law enforcement disruption efforts.

DragonForce is a ransomware affiliate brand that has used double extortion and, in some reporting, a franchise-style panel. CyberAsia treats each leak-site name as a claim. Initial access is the usual mix of VPN, stolen credentials, and commodity loaders. There is no public evidence they need a unique zero-day for mid-market victims.

Patch the edge, kill standing RDP, keep one offline restore that the helpdesk cannot delete. Do not negotiate from the same workstation that still has their note open.

STATUS: ACTIVE CLASSIFICATION: RANSOMWARE SYNDICATE LAST SEEN: Aug 2026

> LINKED_INTEL_REPORTS (1)

> cd ../articles