Find notable cyber news and cases, enriched with sources, timelines, and signals.

DragonForce / Hackledorb pivots from RaaS to a formalized cartel structure

Threat Actor Meta
First reported
Last updated
Happening score
H score 26
1 unique sources, 1 articles

Summary

Hide ▲

Hackledorb has pivoted DragonForce from a conventional ransomware-as-a-service (RaaS) model into a formalized cartel structure, signaling a more organized and durable adversary ecosystem. The shift raises the group's ability to scale operations, coordinate affiliates, and sustain pressure against enterprise victims while blending ransomware with stealthier post-compromise tradecraft.

Related Happenings

Scattered Spider reclassified as a decentralized collective of independent clusters

Threat Actor Meta
H score26 First: 07.07.2026 17:00 Last: 07.07.2026 17:00 Sources 1

About this happening: Scattered Spider has been reclassified as a decentralized cybercrime collective, changing how its persistence and resilience are understood. The shift suggests independe...

Major U.S. services company hit by ransomware attack linked to DragonForce

Incident
H score38 First: 16.06.2026 13:18 Last: 16.06.2026 13:18 Sources 1

How related: the backdoor was deployed against a major U.S. services firm. The name of the company was not disclosed.

About this happening: A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...

Silent Ransom Group shifts from Conti-linked ransomware participation to standalone data-theft extortion

Threat Actor Meta
H score21 First: 07.06.2026 17:09 Last: 07.06.2026 17:09 Sources 1

About this happening: Silent Ransom Group (UNC3753) is a standalone data-theft extortion actor that has operated separately since 2022 after the Conti shutdown, using stolen data and le...

The Gentlemen affiliate-driven RaaS expansion and enterprise scale-up

Threat Actor Meta
H score57 First: 21.04.2026 17:00 Last: 21.04.2026 17:00 Sources 1

About this happening: The Gentlemen ransomware-as-a-service operation is using an operator-maintained EDR-killer portfolio, led by GentleKiller, to disable security software before encrypti...

Fake IT support Havoc campaign

Campaign
H score32 First: 03.03.2026 19:15 Last: 03.03.2026 19:15 Sources 1

About this happening: A fake IT support campaign is using email spam, phone-based social engineering, and Havoc C2 to gain initial access, putting targeted organizations at risk of data e...

Timeline

  1. 18.06.2026 16:30 2 articles · 27d ago

    Hackledorb pivots DragonForce from RaaS to a formalized cartel structure

    Attribution Update

    Hackledorb, the threat actor behind DragonForce, has moved the group from a conventional ransomware-as-a-service model into a highly organized, formalized cartel structure, indicating a more durable and coordinated ransomware operating model.

    Show sources