Threat Actor πŸ‡²πŸ‡Ύ Malaysia

DragonForce

DragonForce is a hacktivist group based in Malaysia that has been involved in cyberattacks targeting government institutions and commercial organizations in India. They have also targeted websites affiliated with Israel and have shown support for pro-Palestinian causes. The group has been observed using defacement attacks, distributed denial-of-service attacks, and data leaks as part of their campaigns. DragonForce Malaysia has demonstrated an ability to adapt and evolve their tactics over time.

Indicators of Compromise 45

Domain comunidadesparentais[.]com[.]br Domain glanz-gmbh[.]de Domain mysimerp[.]net Domain professionalhomebasedbusiness[.]com Domain projetosmecanicos[.]com[.]br Domain safefire[.]jo Domain socialbizsolutions[.]com Domain turnkeyaiagents[.]com Filename 1.EXE Filename Kuailian VPN Filename Kuailian VPN.msi Filename LBB.exe Filename PsExecSvc.exe Filename TechSupV18Fix3.zip Filename Windows Host Widgets.exe Filename Windows Host Widgets_.exe Filename cacheX.txt Filename node.exe SHA-1 not provided SHA-256 048e18416177de2ead251abdf4d89837f6807c6aba4d5b1debe49adfdecbf05c SHA-256 087f002df0a02c8c74f3ba5cd99cf29fb9efff38bf57b3d808e34a5dd4200dd2 SHA-256 142bac0e2148e0d47891b6cd7311195c4acbe33b700fad54a201c52a2bc46219 SHA-256 252a8bb2eb9c96c5e6cc7cab822e2ed0d508032f9350351221781684e86c03ab SHA-256 65ab49119c845801f29a57e8aa177146b2ffbd289d4278109b146f933380f951 SHA-256 6bbf10bcbef7ac5102b54c81137859891a3802dbacd888be90f990d50e18b0b4 SHA-256 6f9fbe29f8cc2788e2bc9d631e0eea2a8e9837076837b55838005a0e654f0a9e SHA-256 821da79d727351dd67ce5df7950e9a3de6647a3cf474bb3a093f67507fed92a6 SHA-256 8284c8676cc22c4b2e66826ac16986da7ddecba1f2776b16771be17bfdc45dc2 SHA-256 82b37a92589dfd4d67ca87eb9e52ac8e682e8e60d2211f59074cd5ccc693013b SHA-256 8395b621bb4415090f232c59fc41d24ea41a519b58eabe512f3ae7d2fdf049a3 SHA-256 8a4033425d36cd99fe23e6faef9764fbf555f362ebdb5b72379342fbbe4c5531 SHA-256 9335f61f8ad276d94455c5b6876fea48152c3cea759f2598c8108ee461fa5759 SHA-256 b16e217cdca19e00c1b68bdfb28ead53b20adeabd6edcd91542f9fbf48942877 SHA-256 b6628d201c2a68d2a3de2a87de7a5acfe21b101a97928e1c8d5c82102d967383 SHA-256 cd078957167e1af4de39aecdb981cd14156fa81d5a9c6ac51e74ae5b6199a12a SHA-256 ce66b8221446c9b6d83f0ce6382f430e519601641e5daaaf1ca7a8a8806cb0b0 SHA-256 d0da2832ae1e13a98f7ce7e33a66c1b0d9797b81f69ece134e4462ea55ac923e SHA-256 d20a3c928761fe00ac522eeb474612b5804cd9108453ea8591106d5d4428428e SHA-256 e45b18c93d187aac5c4486f57483bc87580e15def82a312bfb377ff16eb96b22 SHA-256 ea26980059ef2ad11e99556a4edfa1f8ec769fa9f06aa573b81bedf319954b5 SHA-256 f174c19902523dcf005fa044b6598403a5e5c0a5982398d1bc0dcc5ec1cd351b IP 192[.]36[.]27[.]51 IP 62[.]164[.]177[.]25 Package Braintree.Net Package Jscrambler

MITRE ATT&CK TTPs 47

T1021
Remote Services
Lateral Movement
T1021.001
Remote Desktop Protocol
Lateral Movement
T1021.003
Distributed Component Object Model
Lateral Movement
T1052.001
Exfiltration over USB
Exfiltration
T1053
Scheduled Task/Job
Execution
T1055
Process Injection
Defense Evasion
T1056.001
Keylogging
Collection
T1059.001
PowerShell
Execution
T1068
Exploitation for Privilege Escalation
Privilege Escalation
T1071.001
Web Protocols
Command And Control
T1071.004
DNS
Command And Control
T1078
Valid Accounts
Defense Evasion
T1080
Taint Shared Content
Lateral Movement
T1082
System Information Discovery
Discovery
T1083
File and Directory Discovery
Discovery
T1098
Account Manipulation
Persistence
T1105
Ingress Tool Transfer
Command And Control
T1110
Brute Force
Credential Access
T1114
Email Collection
Collection
T1120
Peripheral Device Discovery
Discovery
T1132
Data Encoding
Command And Control
T1133
External Remote Services
Persistence
T1134
Access Token Manipulation
Defense Evasion
T1190
Exploit Public-Facing Application
Initial Access
T1202
Indirect Command Execution
Defense Evasion
T1210
Exploitation of Remote Services
Lateral Movement
T1219
Remote Access Software
Command And Control
T1222
File and Directory Permissions Modification
Defense Evasion
T1484
Domain or Tenant Policy Modification
Defense Evasion
T1484.001
Group Policy Modification
Defense Evasion
T1486
Data Encrypted for Impact
Impact
T1490
Inhibit System Recovery
Impact
T1491
Defacement
Impact
T1542
Pre-OS Boot
Defense Evasion
T1543.002
Systemd Service
Persistence
T1543.003
Windows Service
Persistence
T1548
Abuse Elevation Control Mechanism
Privilege Escalation
T1557
Adversary-in-the-Middle
Credential Access
T1566
Phishing
Initial Access
T1569.002
Service Execution
Execution
T1573
Encrypted Channel
Command And Control
T1574.001
DLL Search Order Hijacking
Persistence
T1586
Compromise Accounts
Resource Development
T1588
Obtain Capabilities
Resource Development
T1588.001
Malware
Resource Development
T1595
Active Scanning
Reconnaissance
T1659
Content Injection
Initial Access

Source Articles

An analysis of incidents at Brazilian educational institutions
SecureList analyzed cyber incidents at Brazilian educational institutions from 2025 to 2026, identifying ransomware attacks and insider threats. Two major ransomware families observed were LockBit 3 and DragonForce, with attackers using leaked LockBit builders and valid credentials for initial access. In one case, LockBit was deployed via PsExec after disabling defenses using a batch script; in another, DragonForce was delivered via AnyDesk. An insider used a custom Python keylogger to capture credentials on shared machines, storing logs in hidden files later retrieved via USB.
securelist Β·4w ago
Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden
The DragonForce ransomware group, tracked by Symantec as Hackledorb, conducted a sophisticated attack against a U.S. services firm, leveraging custom malware and novel techniques to evade detection. The attackers used a Go-based backdoor named Backdoor.Turn, which abuses Microsoft Teams' TURN relay infrastructure to hide command-and-control (C2) traffic behind legitimate Microsoft domains. They also employed DLL sideloading, BYOVD techniques exploiting vulnerable signed driversβ€”including Huawei’s HWAuidoOs2Ec.sysβ€”and modified system configurations for persistence and lateral movement before deploying the DragonForce ransomware payload.
security-com Β·2mo ago
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
DevMan, a ransomware-as-a-service (RaaS) operation also tracked as Funky Mantis, operates a centralized affiliate portal enabling payload generation, victim management, and payout coordination. The group evolved from affiliations with Qilin, DragonForce, and others, maintaining strong technical similarities to DragonForce ransomware. DevMan promotes attacks on critical infrastructure, including a specialized SCADA-targeting locker designed to cause physical system damage. The operation enforces strict governance over affiliates, uses an 80-20 revenue split, and has claimed 184 victims, primarily in the U.S. across technology, healthcare, and government sectors.
hacker-news Β·1mo ago
⚑ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
Multiple threat actors are leveraging compromised software supply chains, AI-driven attacks, and unpatched vulnerabilities to deploy malware, steal credentials, and conduct ransomware operations. Notable activities include the exploitation of Citrix Bleed 2 (CVE-2025-5777) for DragonForce ransomware deployment, a compromised npm package distributing a Rust-based stealer, and the emergence of HalluSquatting attacks targeting AI coding assistants. Additionally, new backdoors like GigaWiper and RedHook are being used for persistent access and data exfiltration across Windows and Android platforms.
hacker-news Β·1mo ago