Skip to main content
Back to Ransomware Database
Ransomware Group

dragonforce

DragonForce is a major ransomware-as-a-service operation first observed in August 2023 that launched a formal affiliate program offering 80% revenue share, then rebranded as a "ransomware cartel" in 2025, gaining notoriety for high-profile attacks on UK retailers Marks & Spencer, Co-op, and Harrods.

Known victims651

Threat Level

CRITICAL

Tactics, Techniques & Procedures (TTPs)

CredentialTheft

  • Mimikatz

DiscoveryEnum

  • Advanced IP Scanner
  • PingCastle
  • SoftPerfect NetScan

Indicators of Compromise (IOCs)

IP Addresses

1
  • 45.135.232.195

Get Complete IOC Feed

Access our full IOC database via API for integration with your SIEM/SOAR.

Get Started

No credit card required · Free API key

0

Check If You’re Affected

Search our database to see if your organization appears in dragonforce’s victim list.

Try it nowFree⌘K
Try

risk score · threat categories · sources · age · confidence — in one request