← Back to feed
Breaches & RansomwareEmerging1 sourceSep 7, 2026 · 11:50via Malware.news

DragonForce Ransomware | Group Profile, Cartel Alliance & Attack Analysis (2026)

Brief

DragonForce ransomware is a ransomware-as-a-service (RaaS) operation that began as a pro-Palestine hacktivist collective based in Malaysia before pivoting to ransomware, and has since grown into one of the most disruptive extortion brands in the ransomware landscape.

In March 2025, DragonForce publicly restructured itself as a ransomware cartel, and by that autumn it had formed a formal coalition with two of the biggest names in ransomware, LockBit and Qilin , a partnership researchers say is designed to share techniques, resources, and infrastructure across all three groups.

The group’s real-world impact is already measurable: the DragonForce-linked breach of UK retailer Marks & Spencer alone dropped the company’s statutory profit from £391. 4 million to just £3. 4 million. It cost roughly £136 million in direct response expenses.

Read more on Malware.news