Threat Actor π²πΎ Malaysia
DragonForce
DragonForce is a hacktivist group based in Malaysia that has been involved in cyberattacks targeting government institutions and commercial organizations in India. They have also targeted websites affiliated with Israel and have shown support for pro-Palestinian causes. The group has been observed using defacement attacks, distributed denial-of-service attacks, and data leaks as part of their campaigns. DragonForce Malaysia has demonstrated an ability to adapt and evolve their tactics over time.
Indicators of Compromise 45
Domain comunidadesparentais[.]com[.]br Domain glanz-gmbh[.]de Domain mysimerp[.]net Domain professionalhomebasedbusiness[.]com Domain projetosmecanicos[.]com[.]br Domain safefire[.]jo Domain socialbizsolutions[.]com Domain turnkeyaiagents[.]com Filename 1.EXE Filename Kuailian VPN Filename Kuailian VPN.msi Filename LBB.exe Filename PsExecSvc.exe Filename TechSupV18Fix3.zip Filename Windows Host Widgets.exe Filename Windows Host Widgets_.exe Filename cacheX.txt Filename node.exe SHA-1 not provided SHA-256 048e18416177de2ead251abdf4d89837f6807c6aba4d5b1debe49adfdecbf05c SHA-256 087f002df0a02c8c74f3ba5cd99cf29fb9efff38bf57b3d808e34a5dd4200dd2 SHA-256 142bac0e2148e0d47891b6cd7311195c4acbe33b700fad54a201c52a2bc46219 SHA-256 252a8bb2eb9c96c5e6cc7cab822e2ed0d508032f9350351221781684e86c03ab SHA-256 65ab49119c845801f29a57e8aa177146b2ffbd289d4278109b146f933380f951 SHA-256 6bbf10bcbef7ac5102b54c81137859891a3802dbacd888be90f990d50e18b0b4 SHA-256 6f9fbe29f8cc2788e2bc9d631e0eea2a8e9837076837b55838005a0e654f0a9e SHA-256 821da79d727351dd67ce5df7950e9a3de6647a3cf474bb3a093f67507fed92a6 SHA-256 8284c8676cc22c4b2e66826ac16986da7ddecba1f2776b16771be17bfdc45dc2 SHA-256 82b37a92589dfd4d67ca87eb9e52ac8e682e8e60d2211f59074cd5ccc693013b SHA-256 8395b621bb4415090f232c59fc41d24ea41a519b58eabe512f3ae7d2fdf049a3 SHA-256 8a4033425d36cd99fe23e6faef9764fbf555f362ebdb5b72379342fbbe4c5531 SHA-256 9335f61f8ad276d94455c5b6876fea48152c3cea759f2598c8108ee461fa5759 SHA-256 b16e217cdca19e00c1b68bdfb28ead53b20adeabd6edcd91542f9fbf48942877 SHA-256 b6628d201c2a68d2a3de2a87de7a5acfe21b101a97928e1c8d5c82102d967383 SHA-256 cd078957167e1af4de39aecdb981cd14156fa81d5a9c6ac51e74ae5b6199a12a SHA-256 ce66b8221446c9b6d83f0ce6382f430e519601641e5daaaf1ca7a8a8806cb0b0 SHA-256 d0da2832ae1e13a98f7ce7e33a66c1b0d9797b81f69ece134e4462ea55ac923e SHA-256 d20a3c928761fe00ac522eeb474612b5804cd9108453ea8591106d5d4428428e SHA-256 e45b18c93d187aac5c4486f57483bc87580e15def82a312bfb377ff16eb96b22 SHA-256 ea26980059ef2ad11e99556a4edfa1f8ec769fa9f06aa573b81bedf319954b5 SHA-256 f174c19902523dcf005fa044b6598403a5e5c0a5982398d1bc0dcc5ec1cd351b IP 192[.]36[.]27[.]51 IP 62[.]164[.]177[.]25 Package Braintree.Net Package Jscrambler
MITRE ATT&CK TTPs 47
T1021 T1021.001 T1021.003 T1052.001 T1053 T1055 T1056.001 T1059.001 T1068 T1071.001 T1071.004 T1078 T1080 T1082 T1083 T1098 T1105 T1110 T1114 T1120 T1132 T1133 T1134 T1190 T1202 T1210 T1219 T1222 T1484 T1484.001 T1486 T1490 T1491 T1542 T1543.002 T1543.003 T1548 T1557 T1566 T1569.002 T1573 T1574.001 T1586 T1588 T1588.001 T1595 T1659
Remote Services
Lateral Movement
Remote Desktop Protocol
Lateral Movement
Distributed Component Object Model
Lateral Movement
Exfiltration over USB
Exfiltration
Scheduled Task/Job
Execution
Process Injection
Defense Evasion
Keylogging
Collection
PowerShell
Execution
Exploitation for Privilege Escalation
Privilege Escalation
Web Protocols
Command And Control
DNS
Command And Control
Valid Accounts
Defense Evasion
Taint Shared Content
Lateral Movement
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Account Manipulation
Persistence
Ingress Tool Transfer
Command And Control
Brute Force
Credential Access
Email Collection
Collection
Peripheral Device Discovery
Discovery
Data Encoding
Command And Control
External Remote Services
Persistence
Access Token Manipulation
Defense Evasion
Exploit Public-Facing Application
Initial Access
Indirect Command Execution
Defense Evasion
Exploitation of Remote Services
Lateral Movement
Remote Access Software
Command And Control
File and Directory Permissions Modification
Defense Evasion
Domain or Tenant Policy Modification
Defense Evasion
Group Policy Modification
Defense Evasion
Data Encrypted for Impact
Impact
Inhibit System Recovery
Impact
Defacement
Impact
Pre-OS Boot
Defense Evasion
Systemd Service
Persistence
Windows Service
Persistence
Abuse Elevation Control Mechanism
Privilege Escalation
Adversary-in-the-Middle
Credential Access
Phishing
Initial Access
Service Execution
Execution
Encrypted Channel
Command And Control
DLL Search Order Hijacking
Persistence
Compromise Accounts
Resource Development
Obtain Capabilities
Resource Development
Malware
Resource Development
Active Scanning
Reconnaissance
Content Injection
Initial Access
Source Articles
An analysis of incidents at Brazilian educational institutions
SecureList analyzed cyber incidents at Brazilian educational institutions from 2025 to 2026, identifying ransomware attacks and insider threats. Two major ransomware families observed were LockBit 3 and DragonForce, with attackers using leaked LockBit builders and valid credentials for initial access. In one case, LockBit was deployed via PsExec after disabling defenses using a batch script; in another, DragonForce was delivered via AnyDesk. An insider used a custom Python keylogger to capture credentials on shared machines, storing logs in hidden files later retrieved via USB.
securelist Β·4w ago
Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden
The DragonForce ransomware group, tracked by Symantec as Hackledorb, conducted a sophisticated attack against a U.S. services firm, leveraging custom malware and novel techniques to evade detection. The attackers used a Go-based backdoor named Backdoor.Turn, which abuses Microsoft Teams' TURN relay infrastructure to hide command-and-control (C2) traffic behind legitimate Microsoft domains. They also employed DLL sideloading, BYOVD techniques exploiting vulnerable signed driversβincluding Huaweiβs HWAuidoOs2Ec.sysβand modified system configurations for persistence and lateral movement before deploying the DragonForce ransomware payload.
security-com Β·2mo ago
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
DevMan, a ransomware-as-a-service (RaaS) operation also tracked as Funky Mantis, operates a centralized affiliate portal enabling payload generation, victim management, and payout coordination. The group evolved from affiliations with Qilin, DragonForce, and others, maintaining strong technical similarities to DragonForce ransomware. DevMan promotes attacks on critical infrastructure, including a specialized SCADA-targeting locker designed to cause physical system damage. The operation enforces strict governance over affiliates, uses an 80-20 revenue split, and has claimed 184 victims, primarily in the U.S. across technology, healthcare, and government sectors.
hacker-news Β·1mo ago
β‘ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
Multiple threat actors are leveraging compromised software supply chains, AI-driven attacks, and unpatched vulnerabilities to deploy malware, steal credentials, and conduct ransomware operations. Notable activities include the exploitation of Citrix Bleed 2 (CVE-2025-5777) for DragonForce ransomware deployment, a compromised npm package distributing a Rust-based stealer, and the emergence of HalluSquatting attacks targeting AI coding assistants. Additionally, new backdoors like GigaWiper and RedHook are being used for persistent access and data exfiltration across Windows and Android platforms.
hacker-news Β·1mo ago