Back to Ransomware Database
Ransomware Group
dragonforce
DragonForce is a major ransomware-as-a-service operation first observed in August 2023 that launched a formal affiliate program offering 80% revenue share, then rebranded as a "ransomware cartel" in 2025, gaining notoriety for high-profile attacks on UK retailers Marks & Spencer, Co-op, and Harrods.
Known victims651
Threat Level
CRITICAL
Tactics, Techniques & Procedures (TTPs)
CredentialTheft
- Mimikatz
DiscoveryEnum
- Advanced IP Scanner
- PingCastle
- SoftPerfect NetScan
Indicators of Compromise (IOCs)
IP Addresses
1- 45.135.232.195
Get Complete IOC Feed
Access our full IOC database via API for integration with your SIEM/SOAR.
Get StartedNo credit card required · Free API key
Check If You’re Affected
Search our database to see if your organization appears in dragonforce’s victim list.
Try it nowFree⌘K
Try
risk score · threat categories · sources · age · confidence — in one request