dragonforce
RansomwareAbout the group
DragonForce is a major ransomware-as-a-service operation first observed in August 2023 that launched a formal affiliate program offering 80% revenue share, then rebranded as a "ransomware cartel" in 2025, gaining notoriety for high-profile attacks on UK retailers Marks & Spencer, Co-op, and Harrods.
Exploited vulnerabilities
No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.
Impact and victims
The group dragonforce has 10 known ransomware victims. See the most affected sectors and countries and recent victims.
10known victims
10in Brazil
8sectors hit
Activity (12 months)
Most attacked sectors
Professional Services2
Education1
Energy & Utilities1
Financial Services1
Manufacturing1
Other1
Agriculture and Food Production1
Technology1
Most affected countries
🇧🇷 Brasil10
Recent victims
Petrosul Distribuidora, Transportadora e Comércio de Combustíveis Ltda.
Frato
Vermont XCenter
agroprime
novafp.com
fgv.br
C&M Software
Banco Guanabara
Scolari
Igloo Cellulose
References
dragonforce uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.
Explore the AI Autonomous Pentest →