• Home
  • Privacy Policy
  • Terms and Conditions
  • DMCA
  • Disclaimer
  • Contact us
Sunday, November 9, 2025
No Result
View All Result
NEWSLETTER defal
Lebanon Hub
NEWSLETTER
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up
No Result
View All Result
Lebanon Hub
No Result
View All Result

DragonForce targets rivals in a play for dominance – Sophos News

May 21, 2025
in Cyber Security
0
Home Cyber Security
0
VIEWS
Share on FacebookShare on Twitter


DragonForce isn’t just one other ransomware model – it’s a destabilizing power attempting to reshape the ransomware panorama. Counter Risk Unit (CTU) researchers are actively monitoring the evolution of the menace posed by the group.  

Enter the dragon

DragonForce is concerned in high-impact assaults focusing on each conventional IT infrastructure and virtualized environments (e.g., VMware ESXi), with a powerful emphasis on credential theft, Energetic Listing abuse, and knowledge exfiltration. In March 2025, it launched efforts to assert dominance within the ransomware ecosystem by introducing a extra versatile affiliate mannequin and focusing on different ransomware teams. 

A collection of assaults on UK retailers that started in late April introduced this group into sharper focus as third-party stories linked these assaults to DragonForce and the GOLD HARVEST (often known as Scattered Spider) menace group. GOLD HARVEST regularly leverages social engineering, abuse of distant monitoring and administration (RMM) instruments, and multi-factor authentication (MFA) bypass strategies to achieve entry, steal bulk knowledge, and typically deploy ransomware.  

When DragonForce emerged in August 2023, it provided a conventional RaaS scheme. On March 19, 2025, the group introduced a rebrand as a ‘cartel’ to increase its attain, hoping to emulate the success of LockBit and different mature ransomware-as-a-service (RaaS) teams. In follow, it isn’t a cartel operation however an providing that offers associates the pliability to leverage DragonForce’s infrastructure and ransomware instruments whereas working beneath their very own manufacturers (see Determine 1). 

A screen capture of the 19 March 2025 announcement; the intro reads "Today I would like to present to you our new direction, we are starting to work in a new vein, according to a new principle. You no longer have to work under our brand, now you can create your own brand under the auspices of an already proven partner time! We the DragonForce Ransomware cartel present to you 'projects' now you create yourself."

Determine 1: Commercial for the DragonForce cartel. (Supply: Secureworks) 

DragonForce didn’t simply revamp its enterprise mannequin; it started attacking rival operations. The ‘cartel’ put up coincided with defacements of leak websites operated by the BlackLock and Mamona ransomware teams. The defacements appeared to have been performed by DragonForce, as seen within the side-by-side display screen captures in Determine 2. 

Two screens showing the BlackLock and Mamona defacements as described in text

Determine 2: Defaced Mamona (left) and BlackLock (proper) leak websites. (Supply: Secureworks) 

In April, a put up on the RansomHub leak website appeared to advertise the DragonForce cartel, as seen in Determine 3. A DragonForce put up on the RAMP underground discussion board additionally appeared to point that the teams have been working collectively, however the postscript steered that RansomHub won’t help the collaboration (see Determine 4). RansomHub is without doubt one of the most prolific teams to emerge following the LockBit disruption and ALPHV (often known as BlackCat) demise in 2024. 

A screen capture showing the DragonForce mention on RansomHub as described in text

Determine 3: DragonForce cartel point out on RansomHub leak website. (Supply: Secureworks) 

A screen capture showing the "collaboration" -- text reads "DragonForce & RansomHub -- Hi. Don't worry RansomHub will be up soon, they just decided to move to our infrastructure! We are reliable partners. A good example of how 'projects' work, a new option from The DragonForce Ransomware Cartel!" A postscript at the bottom reads "P.S. -- RansomHub hope you are doing well, consider our offer! We are waiting for everyone in our ranks."

Determine 4: DragonForce put up suggesting a collaboration with RansomHub. (Supply: Secureworks) 

Shortly after these posts, the RansomHub leak website went offline. The homepage displayed the message “RansomHub R.I.P 03/03/2025.” The “collaboration” between DragonForce and RansomHub seems to have been extra of a hostile takeover by DragonForce. The ‘koley’ persona, who is thought to be a outstanding RansomHub member, posted a defacement of the DragonForce homepage on RAMP (see Determine 5), together with the message “@dragonforce guess you’ve got traitors…” Extra posts by koley accused DragonForce of working with legislation enforcement, attacking rivals, and telling lies.  

An image showing a crossed-out DragonForce logo and three derpy-looking cartoon dragons

Determine 5: Defacement of the DragonForce leak website shared by RansomHub member ‘koley’. (Supply: Secureworks) 

As of this publication, the DragonForce leak website is again on-line after an prolonged interval of down time. Throughout that interval, the homepage displayed a message stating that it will be up once more quickly, and an identical message seems on the RansomBay leak website (see Determine 6). 

A pair of images; on the left, DragonForce announcement reads "We will be up soon -- Our blog and files server will be up on 29.04.2025 00:00 UTC Thank you for your patience." On the right, the RansomHub announcement reads "Went on a journey... We're still in search for a pirates!"

Determine 6: DragonForce and RansomBay leak website homepages as of Could 2, 2025. (Supply: Secureworks) 

In Could 2025, UK retailer Marks and Spencer was the topic of a major cyberattack that was publicly attributed to GOLD HARVEST (referred to within the reporting as Scattered Spider), though this attribution has not been formally confirmed. This group is a loosely organized cybercriminal collective made up of particular person menace actors who collaborate via a shared community of underground boards and encrypted chat channels utilized by a neighborhood of like-minded people often known as “The Com.” The menace actors on this neighborhood coordinate malicious companies to conduct assaults, change instruments, and share techniques inside this decentralized ecosystem. GOLD HARVEST reportedly deployed the DragonForce ransomware on this assault.  

GOLD HARVEST has been identified to function as a ransomware affiliate, deploying ALPHV ransomware in assaults on MGM Resorts in 2023 and reportedly utilizing RansomHub in assaults all through 2024. The menace actors make the most of a variety of techniques, strategies, and procedures (TTPs) of their assaults however are identified for his or her efficient use of social engineering. They typically acquire entry to organizations by focusing on IT assist desks. Public attribution of the Marks and Spencer assault could also be predicated on the idea that the assault began with social engineering, maybe focusing on assist desk employees. 

Social engineering is a common menace throughout the cyber panorama and isn’t distinctive to GOLD HARVEST, though the group has been adept at utilizing this method through e-mail and phone calls. There’s rising interaction between social engineering and stolen credentials. GOLD HARVEST is identified to make use of commodity infostealers similar to Vidar and Raccoon, which acquire browser-saved passwords, cookies, and session tokens. These credentials can allow preliminary entry immediately or help extra convincing social engineering makes an attempt by permitting attackers to reference inner programs or mimic reputable worker conduct. 

DragonForce has claimed two assaults impacting UK retailers. These assaults spotlight the necessity for vigilance by corporations within the retail sector. The interior warfare amongst ransomware teams is disruptive to their very own operations however doesn’t scale back threat to organizations. In actual fact, it could result in extra erratic, opportunistic assaults as teams scramble to claim dominance and monetize stolen knowledge in new methods. Organizations should subsequently revisit their incident response, menace intelligence, and third-party threat administration methods to stay resilient in an more and more chaotic menace surroundings. 

Suggestions for defenders

Whereas technical controls stay important for detecting and mitigating GOLD HARVEST and DragonForce exercise, they have to be bolstered by sturdy inner processes and constant human vigilance. These assaults reinforce that technical compromises typically start with social compromise. Conversations are regularly the preliminary level of compromise, not exploits. Organizations should scale back their publicity to social engineering by combining technical controls with procedural self-discipline. CTU researchers suggest that organizations take the next actions to mitigate the dangers of those assaults: 

  • Deploy browser isolation and password managers to stop harvesting of saved credentials. 
  • Implement endpoint detection for infostealer exercise, together with credential and session cookie theft. 
  • Make the most of an id monitoring resolution that makes use of darkish net sources and menace intel feeds to repeatedly monitor for compromised credentials. 
  • Implement strict id verification protocols for IT help and assist desk interactions. 
  • Set up clear escalation paths to empower front-line employees to withstand uncommon or pressing requests till they are often verified. 
  • Conduct common tabletop workouts that simulate social engineering and insider menace situations. 



Source link

Tags: dominanceDragonForceNewsPlayrivalsSophosTargets
Next Post
How to keep your Apple devices safe from AirPlay attacks

How to keep your Apple devices safe from AirPlay attacks

Beirut, LB
28°
Partly Cloudy
06:2218:40 EEST
Feels like: 30°C
Wind: 11km/h SW
Humidity: 58%
Pressure: 1011.18mbar
UV index: 7
SatSunMon
30°C / 25°C
31°C / 26°C
31°C / 26°C
powered by Weather Atlas

Recent News

Scientists Just Solved the Mystery of the Moon’s Lopsided Dust Halo

Scientists Just Solved the Mystery of the Moon’s Lopsided Dust Halo

November 9, 2025
Drilling Down on Uncle Sam’s Proposed TP-Link Ban – Krebs on Security

Drilling Down on Uncle Sam’s Proposed TP-Link Ban – Krebs on Security

November 9, 2025
What Happened To The Cast Of Taxi?

What Happened To The Cast Of Taxi?

November 9, 2025
How Much Money She’s Worth Today – Hollywood Life

How Much Money She’s Worth Today – Hollywood Life

November 9, 2025
Rock Hall Welcomes Soundgarden, White Stripes, Outkast

Rock Hall Welcomes Soundgarden, White Stripes, Outkast

November 9, 2025
Bitcoin Rebounds Above 4K as Institutional Interest Resumes Despite Recent ETF Outflows

Bitcoin Rebounds Above $104K as Institutional Interest Resumes Despite Recent ETF Outflows

November 9, 2025
Bitcoin UTXO Age Bands Put Local Bottom At K — Here’s Why

Bitcoin UTXO Age Bands Put Local Bottom At $95K — Here’s Why

November 9, 2025
Trump Pledges to Sign CLARITY Act, Fast-Tracking U.S. Crypto Rules as China Accelerates

Trump Pledges to Sign CLARITY Act, Fast-Tracking U.S. Crypto Rules as China Accelerates

November 9, 2025
Lebanon Hub

Get the Latest Lebanon News and world News on LebanonHub.com. Local News, Sports, Technology, Music, Celebrity, Gaming News and Cryptocurrency Updates.

Category

  • Altcoin
  • Australia
  • Bitcoin
  • Blockchain
  • Celebrity
  • Cyber Security
  • Ethereum
  • Exchange
  • Litecoin
  • Local News
  • Mobile
  • Movies
  • Music
  • New Released
  • PC
  • PlayStation
  • Popular
  • Reviews
  • Sports
  • Startups
  • Technology
  • TV
  • XBOX

Recent News

Scientists Just Solved the Mystery of the Moon’s Lopsided Dust Halo

Scientists Just Solved the Mystery of the Moon’s Lopsided Dust Halo

November 9, 2025
Drilling Down on Uncle Sam’s Proposed TP-Link Ban – Krebs on Security

Drilling Down on Uncle Sam’s Proposed TP-Link Ban – Krebs on Security

November 9, 2025
  • Home
  • DMCA
  • Disclaimer
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2022 - Lebanon Hub.

No Result
View All Result
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up

Copyright © 2022 - Lebanon Hub.