Back to Intelligence

DRAGONFORCE Ransomware Gang: 4 New Leak-Site Listings Across Manufacturing, Energy & Technology — Claims Analysis & Detection Rules

SA
Security Arsenal Team
October 11, 2026
16 min read

Classification: TLP:CLEAR | Publication Date: 2026-10-11 | Source: ransomware.live leak-site monitoring | Nature of data: Unverified threat-actor claims

Executive Summary

DRAGONFORCE, a ransomware-as-a-service (RaaS) operation that has remained a persistent fixture of the extortion ecosystem, published four new listings on its dark web leak site between 2026-10-07 and 2026-10-11. The gang claims to have compromised organizations in the Manufacturing, Energy & Utilities, and Technology sectors, spanning Peru, Taiwan, Brazil, and France.

All four listings are unverified claims by a criminal actor. Every listing in this window was independently observed by two separate leak-site crawlers, which confirms the gang made these postings — it does not confirm that any breach occurred. Security teams at organizations matching the victim profile — mid-market manufacturing, fuel distribution, and regional technology services — should treat this as a sector-exposure signal: review the CVE-based perimeter posture and deploy the detection content in this briefing, rather than waiting for a leak-site notification involving your own name.

Key observations:

  • 4 listings in 5 days — a moderate but steady operational tempo consistent with DRAGONFORCE's historical cadence.
  • Manufacturing concentration: 2 of 4 listings (TQC S.A. in Peru, TEXMA International Co., Ltd in Taiwan) fall in Manufacturing, continuing the gang's documented preference for production environments where downtime pressure accelerates payment decisions.
  • No breach confirmation exists for any named organization. Treat each listing as an accusation requiring independent verification.
  • Sector-relevant KEV exposure: Multiple CISA KEV entries with confirmed ransomware use (VMware vCenter, Cisco FMC, Check Point) map to the infrastructure stacks typical of these sectors. No evidence links any specific CVE to any specific named listing — this is a hypothesis for defensive prioritization only.

Sourcing & Verification

This briefing is built from monitoring of DRAGONFORCE's .onion leak site via ransomware.live. Readers must understand exactly what this data is — and what it is not.

  • Corroboration status: 4 of 4 listings in this window were independently observed by a second leak-site crawler; 0 listings appear on a single source only. Multi-source observation means two independent crawlers saw the gang publish the claim. It does not mean the underlying intrusion is real.
  • A listing is a threat actor's claim, not a confirmed breach. Inclusion in this briefing reflects what DRAGONFORCE has posted. No tier of crawler corroboration confirms a compromise — only the named organization, its forensic investigators, or its regulator can do that.
  • A named organization may dispute the listing, and a denial is likewise not proof the claim is false. Disclosure obligations vary by jurisdiction and sector, and not every incident is legally reportable. Neither silence nor denial settles the question. We deliberately avoid stating that any organization "was breached" or "suffered an attack."
  • Corrections policy: Security Arsenal will publish corrections if any listing is withdrawn, disputed with evidence, or confirmed. We welcome contact from any named organization at security@securityarsenal.com.

Threat Actor Profile — DRAGONFORCE

Aliases & branding: DRAGONFORCE operates under its own brand and has marketed a "RaaS 2.0" model on underground forums, positioning itself as an affiliate-friendly platform with customizable branding — affiliates can, in effect, run their own "brand" on DRAGONFORCE infrastructure. Analysts should treat victim listings as potentially attributable to any of multiple affiliate crews operating under the DRAGONFORCE umbrella.

Operating model: Ransomware-as-a-Service. DRAGONFORCE provides the encryptor, negotiation infrastructure, leak site, and (per its own advertisements) ancillary services such as DDoS pressure and call-center harassment, while affiliates handle intrusion and deployment. Revenue splits are advertised in the 70–80% range to affiliates.

Typical ransom demands: Demands observed across the ecosystem generally scale to victim revenue, commonly ranging from the mid–six figures to low seven figures (USD). Manufacturing and energy distribution victims — organizations with high downtime cost but often thin security budgets — are classic mid-demand targets.

Known initial access methods (historical, ecosystem-level):

  • Perimeter appliance exploitation — VPN gateways, firewalls, and remote access infrastructure (this is why the Check Point, Cisco FMC, and VMware KEV entries below matter for sectors DRAGONFORCE lists).
  • Phishing with macro-enabled documents or malicious loaders as a secondary vector.
  • Exposed RDP / brute-forced or purchased RDP credentials via initial access brokers (IABs).
  • Supply chain / MSP pivoting in a minority of cases.

Double extortion: Yes — data theft precedes encryption, with leak-site publication used as pressure. The four listings analyzed here represent the publicity phase of that model; publication typically follows failed or stalled negotiation.

Average dwell time: Ecosystem reporting on comparable RaaS operations places dwell time from initial access to detonation in the 3–14 day range, with exfiltration usually occurring in the final 48–72 hours before encryption. This is the defender's window: the pre-encryption staging phase is noisy and detectable.

Current Campaign Analysis

Sectors Targeted

Organization (as listed by DRAGONFORCE)SectorCountryPublishedCorroboration
TQC S.A.ManufacturingPE2026-10-11Multi-source crawler observation (claim only)
TEXMA International Co., LtdManufacturingTW2026-10-10Multi-source crawler observation (claim only)
Petrosul Distribuidora, Transportadora e Comércio de Combustíveis Ltda.Energy & UtilitiesBR2026-10-07Multi-source crawler observation (claim only)
RÉSOTechnologyFR2026-10-07Multi-source crawler observation (claim only)

Two Manufacturing listings anchor this batch. DRAGONFORCE and its affiliates have historically favored manufacturing for a simple economic reason: production-line downtime is immediately quantifiable, and victim organizations frequently lack mature SOC coverage. The Energy & Utilities listing (a Brazilian fuel distributor) fits the same logic — logistics and distribution operations cannot tolerate extended outage. The Technology listing (France) is consistent with opportunistic targeting of regional IT services firms, which can also serve as pivot points into downstream customers.

Geographic Concentration

No geographic concentration exists in this window: one listing each in Peru, Taiwan, Brazil, and France. This spread is characteristic of an affiliate-driven RaaS — geography follows wherever affiliates' access brokers have inventory, not a strategic regional focus. The notable pattern is that none of the four listings are US-based organizations, which may reflect affiliate preference for jurisdictions with weaker disclosure regimes and lower law-enforcement heat. Treat that as an observation of this window, not a rule.

Victim Profile

Based on sector norms, the listed organizations appear to be mid-market enterprises — regional manufacturers, a fuel distributor, and a technology services firm. Typical revenue bands for this victim class range from roughly $10M to $250M USD. These are organizations large enough to pay meaningful ransoms but frequently below the maturity threshold for 24/7 detection coverage — precisely the RaaS sweet spot.

Posting Frequency & Escalation

Four listings in five days (2026-10-07 through 2026-10-11), including back-to-back postings on 10-10 and 10-11, indicates an active pipeline rather than a burst-and-pause cycle. Escalation pattern to watch: DRAGONFORCE historically moves from name-only listing → data-sample publication → countdown timers → full dump. Organizations that discover themselves named should assume exfiltrated data exists in the gang's possession if the claim is genuine and activate counsel, IR retainer, and notification analysis immediately.

CVE Exposure — Hypothesis Only

We have no evidence linking any specific CVE to any specific listing above. What we can say: DRAGONFORCE affiliates are known to favor perimeter-appliance exploitation, and the following CISA KEV entries — all with confirmed ransomware use — represent exactly the exposure class present in manufacturing, energy distribution, and regional technology stacks:

  • CVE-2026-50751 — Check Point Security Gateway improper authentication (IKEv1). VPN gateways are a top-three initial access vector for this ecosystem.
  • CVE-2026-20316 — Cisco Secure FMC hard-coded password. Management-plane compromise of the firewall stack.
  • CVE-2026-59310 — VMware vCenter path traversal. Hypervisor management-plane access enables mass-encryption of virtualized estates — the highest-impact detonation scenario.
  • CVE-2026-63077 — JetBrains TeamCity deserialization. CI/CD compromise is relevant to the Technology-sector listing profile and supply-chain pivot risk.
  • CVE-2026-48027 — Nx Console embedded malicious code. Developer-workstation supply chain vector; relevant to technology firms.

Defensive action: If any of these products are in your estate and unpatched, treat them as Priority 1 this week regardless of whether DRAGONFORCE specifically exploited them.

Detection Engineering

The detections below target TTPs characteristic of DRAGONFORCE affiliates and the broader RaaS playbook: perimeter access abuse, hands-on-keyboard lateral movement, and pre-encryption staging. They are written to be environment-agnostic; tune thresholds to your baseline.

YAML
---
title: DRAGONFORCE - Suspicious VPN/Firewall Authentication Anomalies
description: Detects authentication patterns consistent with perimeter appliance exploitation and credential-based access used by ransomware affiliates - impossible travel, off-hours logins, and brute-force bursts against VPN gateways
id: 8f3a1c2e-7b4d-4e9f-a1c5-d6e7f8a9b0c1
status: experimental
author: Security Arsenal Threat Intel
date: 2026/10/11
references:
    - https://securityarsenal.com/darkside
logsource:
    category: authentication
    product: firewall
detection:
    selection_failed:
        EventType: 'authentication_failure'
    selection_success:
        EventType: 'authentication_success'
    timeframe: 10m
    condition: selection_failed | count() by SourceIP >= 10 or selection_success
filter_main:
    SourceIP:
        - '10.0.0.0/8'
        - '172.16.0.0/12'
        - '192.168.0.0/16'
falsepositives:
    - Legitimate VPN users with mistyped credentials
    - Service accounts with retry loops
level: high
tags:
    - attack.initial_access
    - attack.t1133
    - attack.t1110
    - attack.t1190
---
title: DRAGONFORCE - Lateral Movement via PsExec or WMI Remote Execution
description: Detects PsExec service installation and WMI remote process execution consistent with ransomware affiliate lateral movement prior to mass deployment
id: 9d2b4f6a-1c3e-4a7b-b2d4-e5f6a7b8c9d0
status: experimental
author: Security Arsenal Threat Intel
date: 2026/10/11
references:
    - https://securityarsenal.com/darkside
logsource:
    category: process_creation
    product: windows
detection:
    selection_psexec:
        - Image|endswith: '\PSEXESVC.exe'
        - CommandLine|contains|all:
            - '-s'
            - '\\'
    selection_wmi:
        ParentImage|endswith: '\WmiPrvSE.exe'
        Image|endswith:
            - '\cmd.exe'
            - '\powershell.exe'
            - '\pwsh.exe'
    selection_admin_share:
        CommandLine|contains:
            - '\\ADMIN$'
            - '\\C$\\Windows'
    condition: 1 of selection_*
falsepositives:
    - Legitimate administrative tooling (SCCM, PDQ, BigFix)
    - IT helpdesk remote support activity
level: high
tags:
    - attack.lateral_movement
    - attack.t1021.002
    - attack.t1047
    - attack.t1569.002
---
title: DRAGONFORCE - Pre-Encryption Data Staging and Shadow Copy Tampering
description: Detects volume shadow copy deletion and mass-compression staging behavior characteristic of ransomware pre-detonation phase including RaaS operations like DRAGONFORCE
id: 7e1c5d3b-2f4a-4b8c-c3e5-f6a7b8c9d0e1
status: experimental
author: Security Arsenal Threat Intel
date: 2026/10/11
references:
    - https://securityarsenal.com/darkside
logsource:
    category: process_creation
    product: windows
detection:
    selection_vss:
        - Image|endswith: '\vssadmin.exe'
          CommandLine|contains:
            - 'delete shadows'
            - 'resize shadowstorage'
        - Image|endswith: '\wmic.exe'
          CommandLine|contains: 'shadowcopy'
        - Image|endswith: '\bcdedit.exe'
          CommandLine|contains: 'recoveryenabled'
    selection_staging:
        Image|endswith:
            - '\rar.exe'
            - '\7z.exe'
            - '\7za.exe'
            - '\winzip.exe'
        CommandLine|contains:
            - ' -a '
            - ' -p'
            - 'a -t'
    condition: selection_vss or selection_staging
falsepositives:
    - Backup administrators performing legitimate shadow copy maintenance
    - Developers archiving build artifacts
level: critical
tags:
    - attack.impact
    - attack.t1490
    - attack.collection
    - attack.t1560.001

The following Sentinel hunt query identifies pre-ransomware staging behavior — a burst of remote execution followed by compression tooling and shadow copy access on the same host within a 24-hour window, which maps to the DRAGONFORCE affiliate playbook in its final hours before detonation.

KQL — Microsoft Sentinel / Defender
// DRAGONFORCE pre-detonation staging hunt: lateral movement -> archiving -> shadow tampering within 24h
let Lookback = 7d;
let Window = 24h;
let LateralEvents =
    SecurityEvent
    | where TimeGenerated > ago(Lookback)
    | where EventID in (4624, 7045)
    | where (EventID == 4624 and LogonType in (3, 10) and IpAddress !startswith "10." and IpAddress !startswith "192.168.")
        or (EventID == 7045 and ServiceName has_any ("PSEXESVC", "RemCom", "WinRMSvc"))
    | summarize LateralCount = count(), FirstLateral = min(TimeGenerated) by Computer, Account;
let ProcessEvents =
    DeviceProcessEvents
    | where TimeGenerated > ago(Lookback)
    | where FileName in~ ("vssadmin.exe", "bcdedit.exe", "wbadmin.exe")
        and ProcessCommandLine has_any ("delete shadows", "resize shadowstorage", "recoveryenabled", "delete catalog")
    | summarize ShadowTamper = count(), FirstTamper = min(TimeGenerated), TamperCmds = make_set(ProcessCommandLine, 5) by DeviceName;
let ArchiveEvents =
    DeviceProcessEvents
    | where TimeGenerated > ago(Lookback)
    | where FileName in~ ("rar.exe", "7z.exe", "7za.exe", "winrar.exe")
        and ProcessCommandLine has_any (" -a", " -p", "a -t", "-m5")
    | summarize ArchiveRuns = count(), ArchiveCmds = make_set(ProcessCommandLine, 5) by DeviceName;
LateralEvents
| extend DeviceName = Computer
| join kind=inner (ShadowTamper) on DeviceName
| join kind=inner (ArchiveEvents) on DeviceName
| where FirstTamper between (FirstLateral .. FirstLateral + Window)
| project DeviceName, Account, LateralCount, ArchiveRuns, ArchiveCmds, ShadowTamper, TamperCmds, FirstLateral, FirstTamper
| sort by ShadowTamper desc

The following rapid-response script can be run by an on-call responder on any Windows host suspected of involvement. It enumerates the three highest-signal artifacts for this threat class: RDP exposure, recently created scheduled tasks (a common persistence mechanism), and volume shadow copy status.

PowerShell
# DRAGONFORCE Rapid Triage Script - Security Arsenal
# Run as Administrator on any host suspected of staging activity.
# Output: consolidated triage report to C:\IR-Triage-<hostname>-<date>.txt

$ReportPath = "C:\IR-Triage-$env:COMPUTERNAME-$(Get-Date -Format 'yyyyMMdd-HHmm').txt"
"=== DRAGONFORCE Rapid Triage - $env:COMPUTERNAME - $(Get-Date) ===" | Out-File $ReportPath

# 1. Check RDP exposure and recent RDP logons
"`n[1] RDP CONFIGURATION" | Out-File $ReportPath -Append
$rdp = Get-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -ErrorAction SilentlyContinue
"RDP Enabled (0=enabled): $($rdp.fDenyTSConnections)" | Out-File $ReportPath -Append
$nla = Get-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -ErrorAction SilentlyContinue
"NLA Enabled (1=yes, 0=no - RISK if 0): $($nla.UserAuthentication)" | Out-File $ReportPath -Append
Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue |
    ForEach-Object { "LISTENING on 3389 - PID $($_.OwningProcess)" | Out-File $ReportPath -Append }

# 2. Scheduled tasks created or modified in the last 7 days
"`n[2] SCHEDULED TASKS MODIFIED IN LAST 7 DAYS" | Out-File $ReportPath -Append
Get-ScheduledTask | Where-Object { $_.Date -and ([datetime]$_.Date) -gt (Get-Date).AddDays(-7) } |
    ForEach-Object {
        $action = ($_.Actions | Select-Object -First 1).Execute
        "[$($_.Date)] $($_.TaskPath)$($_.TaskName) -> $action" | Out-File $ReportPath -Append
    }

# 3. Volume shadow copy status (tampering indicator)
"`n[3] VOLUME SHADOW COPY STATUS" | Out-File $ReportPath -Append
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
if (-not $shadows) {
    "WARNING: No shadow copies present. Verify this is expected - deletion is a pre-encryption indicator." | Out-File $ReportPath -Append
} else {
    $shadows | ForEach-Object { "ShadowCopy: $($_.ID) created $($_.InstallDate) on $($_.DeviceObject)" | Out-File $ReportPath -Append }
}
$vss = Get-Service VSS
"VSS Service State: $($vss.Status) / StartType: $($vss.StartType)" | Out-File $ReportPath -Append

# 4. Recent suspicious process artifacts (compression + mass file access)
"`n[4] ARCHIVING TOOL PRESENCE" | Out-File $ReportPath -Append
foreach ($tool in 'rar.exe','7z.exe','7za.exe','winrar.exe') {
    $found = Get-ChildItem -Path 'C:\Users','C:\ProgramData','C:\Windows\Temp' -Recurse -Filter $tool -ErrorAction SilentlyContinue | Select-Object -First 5
    $found | ForEach-Object { "FOUND: $($_.FullName) (modified $($_.LastWriteTime))" | Out-File $ReportPath -Append }
}

"`n=== TRIAGE COMPLETE - Review $ReportPath and escalate any WARNING lines to IR ===" | Out-File $ReportPath -Append
Write-Host "Triage report written to $ReportPath" -ForegroundColor Cyan

Incident Response Priorities

T-Minus Detection Checklist — Before Encryption Fires

DRAGONFORCE affiliates follow a recognizable pre-detonation sequence. If you see two or more of the following on the same host or within the same 48-hour window, treat it as a potential pre-ransomware staging event and escalate immediately:

  1. Unusual archiving activity — rar.exe, 7z.exe, or winrar.exe running with password flags against file shares or user directories.
  2. Shadow copy deletion attempts — vssadmin, wmic shadowcopy, bcdedit recoveryenabled modifications, or VSS service stops outside of backup windows.
  3. New service installations with random or typosquatted names (Event ID 7045) — PsExec-style lateral movement.
  4. Cloud sync/exfil tooling — rclone.exe, MEGAsync, FileZilla, or curl/wget against unfamiliar external endpoints, especially to anonymous file-sharing services.
  5. Off-hours RDP/VPN authentication from infrastructure or accounts that have never previously connected at those times.
  6. EDR tampering events — sensor stops, exclusions added, or agent uninstall attempts.

Critical Assets Historically Prioritized for Exfiltration

Based on the RaaS double-extortion playbook and the sectors listed this week:

  • ERP/finance exports — payroll, banking details, tax filings (maximum legal exposure, maximum pressure).
  • Engineering and product data — CAD files, formulas, BOMs from manufacturing environments (TQC/TEXMA victim class).
  • Customer contracts and pricing — distribution agreements in the fuel/energy sector.
  • HR records — identity documents used as proof-of-breach samples on leak sites.
  • Email archives of executives — negotiation leverage.

Containment Actions, Ordered by Urgency

  1. Isolate, don't power off suspected staging hosts — preserve memory for forensics; network isolation stops exfil in progress.
  2. Disable the implicated identity — force password reset and revoke all sessions/tokens for any account seen in anomalous lateral movement. Assume Kerberos ticket theft; reset krbtgt twice if domain-wide compromise is plausible.
  3. Block egress to known exfil destinations at the proxy/firewall: rclone endpoints, Mega, Temp.sh, transfer.sh, anonymous FTP.
  4. Snapshot and verify backups immediately — confirm immutability, confirm offline copies exist, and protect backup infrastructure credentials (Veeam/Commvault compromise is a standard pre-detonation step).
  5. Preserve evidence: firewall/VPN logs for the preceding 30+ days, EDR telemetry, and the leak-site listing itself (screenshot with timestamps) for legal and insurance purposes.
  6. Engage counsel before any contact with the actor. If your organization appears on this leak site, notification obligations, sanctions exposure, and negotiation strategy are legal questions first.

Hardening Recommendations

Immediate (24 Hours)

  • Patch or mitigate the KEV perimeter stack: Check Point Security Gateway (CVE-2026-50751), Cisco Secure FMC (CVE-2026-20316), and VMware vCenter (CVE-2026-59310). If patching is not possible today, isolate management interfaces to a dedicated admin VLAN with jump-host-only access.
  • Enforce MFA on all remote access — VPN, RDP gateways, and any web-facing portal. Disable NLA-off RDP; restrict RDP to VPN-authenticated sources only.
  • Block execution of archiving tools by non-admin users via AppLocker/WDAC rules covering rar.exe, 7z.exe, and unsigned compression binaries in user-writable paths.
  • Enable and alert on tamper protection for your EDR platform; alert on any VSS deletion command line organization-wide.
  • Deploy the Sigma rules and Sentinel query above to your SIEM and validate they fire in a test harness.

Short-Term (2 Weeks)

  • Segment production/OT-adjacent networks from IT: the manufacturing victim profile in this campaign succeeds when flat networks let a single foothold reach the plant floor. Enforce deny-by-default east-west rules.
  • Deploy identity threat detection: alert on DCSync-style replication requests, abnormal Kerberos ticket requests, and new admin-group memberships.
  • Immutable, isolated backups: move at least one backup copy to WORM storage or an isolated cloud vault with separate credentials and MFA. Test a restore this month — not a backup, a restore.
  • Attack surface reduction: enumerate and close internet-exposed RDP, orphaned VPN concentrators, and unused firewall management interfaces. Subscribe to external attack surface monitoring.
  • Tabletop the leak-site scenario: run an exercise where your organization appears on a RaaS leak site. Pre-decide who calls counsel, who talks to insurers, who handles media, and what the public statement says. The first hour is not the time to write policy.

Related Resources

Security Arsenal Incident Response

Managed SOC & MDR Services

AlertMonitor Threat Detection

From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.