Dragonforce
Also known as DragonForce, Hackledorb
Reports
147
First seen
Sep 8, 2025
Last seen
Aug 13, 2026
Motivation
Financial
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Victim regions
×3×32
United States×32
United Kingdom×7
United Arab Emirates×5
India×4
Canada×4
Italy×3
Hong Kong SAR China×3
China×3
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1486 Data Encrypted for Impact ×12T1190 Exploit Public-Facing Application ×10T1566 Phishing ×9T1078 Valid Accounts ×6T1068 Exploitation for Privilege Escalation ×6T1562.001 Impair Defenses: Disable or Modify Tools ×6T1219 Remote Access Software ×5T1021 Remote Services ×5T1059 Command and Scripting Interpreter ×5T1110 Brute Force ×4T1133 External Remote Services ×4T1195 Supply Chain Compromise ×4
Indicators
domain ×284filename ×123cve ×120ip_v4 ×100hash_md5 ×41hash_sha1 ×25hash_sha256 ×19registry_key ×5email ×4url ×2bitcoin_address ×1
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2025-5777 (exploited)CVE-2023-52271 (exploited)CVE-2025-61155 (exploited)CVE-2025-1055 (exploited)CVE-2024-50383 (exploited)CVE-2026-18236CVE-2024-40766 (exploited)CVE-2026-1207 (exploited)CVE-2024-47575 (exploited)CVE-2026-1340 (exploited)CVE-2026-15409 (exploited)CVE-2026-15410 (exploited)CVE-2026-20685CVE-2026-18497CVE-2026-20272CVE-2026-18830CVE-2024-42009 (exploited)CVE-2026-25089 (exploited)CVE-2026-33825 (exploited)CVE-2023-4966 (exploited)
Recent reports
Medium