DragonForce rebrands as a ransomware cartel and expands its affiliate model
Threat Actor Meta
Summary
Hide ▲
Show ▼
DragonForce rebranded itself as a ransomware cartel in 2025, widening its affiliate model and lowering entry barriers for new operators. The shift matters because the group now offers 80% of profits, customizable encryptors, and infrastructure, which can accelerate ransomware scale and reach. It also reflects a broader move toward cooperative cybercrime ecosystems that make defense more difficult.
Related Happenings
TeamPCP and Vect partner to turn supply-chain compromises into ransomware follow-on campaigns
Threat Actor Meta
First: 31.03.2026 15:15
Last: 31.03.2026 15:15
Sources 1
About this happening:
TeamPCP and **Vect ransomware group** are linking **supply-chain compromises** to **follow-on ransomware campaigns**, broadening extortion risk for affected organizations. The shi...
TeamPCP and Vect partner to turn supply-chain compromises into ransomware follow-on campaigns
Threat Actor MetaAbout this happening: TeamPCP and **Vect ransomware group** are linking **supply-chain compromises** to **follow-on ransomware campaigns**, broadening extortion risk for affected organizations. The shi...
Beast ransomware group’s RaaS model and shared TTPs exposed through an open server
Threat Actor Meta
First: 20.03.2026 18:31
Last: 20.03.2026 18:31
Sources 1
About this happening:
An exposed **Beast ransomware group** server now shows its **RaaS operating model** and reusable toolset, complicating attribution across ransomware crews. The recovered materials...
Beast ransomware group’s RaaS model and shared TTPs exposed through an open server
Threat Actor MetaAbout this happening: An exposed **Beast ransomware group** server now shows its **RaaS operating model** and reusable toolset, complicating attribution across ransomware crews. The recovered materials...
The Gentlemen RaaS split exposed by hastalamuerte
Threat Actor Meta
First: 19.03.2026 18:00
Last: 19.03.2026 18:00
Sources 1
About this happening:
**hastalamuerte** exposed the internal workings of **The Gentlemen** ransomware group, revealing a **Qilin-related RaaS split** that shows how affiliate-driven ecosystems can rapi...
The Gentlemen RaaS split exposed by hastalamuerte
Threat Actor MetaAbout this happening: **hastalamuerte** exposed the internal workings of **The Gentlemen** ransomware group, revealing a **Qilin-related RaaS split** that shows how affiliate-driven ecosystems can rapi...
2025 Ransomware trend toward built-in Windows tooling and lower ransom payment rates
Target Trend
First: 17.03.2026 23:41
Last: 17.03.2026 23:41
Sources 1
About this happening:
**Ransomware operators** are increasingly leaning on **built-in Windows tooling** while **ransom payment rates** continue to decline across **2025**, weakening extortion returns f...
2025 Ransomware trend toward built-in Windows tooling and lower ransom payment rates
Target TrendAbout this happening: **Ransomware operators** are increasingly leaning on **built-in Windows tooling** while **ransom payment rates** continue to decline across **2025**, weakening extortion returns f...
Ransomware ecosystem fragments into smaller agile cells in 2025
Threat Actor Meta
First: 18.02.2026 13:30
Last: 18.02.2026 13:30
Sources 1
About this happening:
**Ransomware** activity in **2025** is becoming more fragmented and harder to track, with **124 groups** and **73 new groups** signaling a more crowded threat market. The shift ma...
Ransomware ecosystem fragments into smaller agile cells in 2025
Threat Actor MetaAbout this happening: **Ransomware** activity in **2025** is becoming more fragmented and harder to track, with **124 groups** and **73 new groups** signaling a more crowded threat market. The shift ma...
Timeline
-
03.12.2025 17:05 2 articles · 5mo ago
DragonForce rebrands as a ransomware cartel and expands its affiliate model
Initial DisclosureIn **2025**, DragonForce shifted into a cartel-style model that monetizes affiliates with a large profit split and shared infrastructure. That change lowered the bar for new operators and expanded the group’s ransomware reach.
Show sources
- Deep dive into DragonForce ransomware and its Scattered Spider connection — www.bleepingcomputer.com — 03.12.2025 17:05
- Deep dive into DragonForce ransomware and its Scattered Spider connection — www.bleepingcomputer.com — 03.12.2025 17:05