Visualização normal

Antes de ontemAnalyst
  • ✇@BushidoToken Threat Intel
  • UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026 BushidoToken
     What HappenedThroughout H1 2026, the Qilin ransomware-as-a-service (RaaS) Tor data leak site (DLS) listed the most UK-based victims out of all ransomware gangs, with up to 37 British organisations hit in total. Qilin's victim count is followed by DragonForce with 21 victims listed, and TheGentlemen with 18 listed.The fallout from the Qilin attack on the UK National Health Service (NHS) supplier, Synnovis, in 2024 persists as well. On 1 June 2026, the Bedfordshire Hospitals NHS Foundation Trust
     

UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026

5 de Agosto de 2026, 05:00

 

What Happened

  • Throughout H1 2026, the Qilin ransomware-as-a-service (RaaS) Tor data leak site (DLS) listed the most UK-based victims out of all ransomware gangs, with up to 37 British organisations hit in total. Qilin's victim count is followed by DragonForce with 21 victims listed, and TheGentlemen with 18 listed.
  • The fallout from the Qilin attack on the UK National Health Service (NHS) supplier, Synnovis, in 2024 persists as well. On 1 June 2026, the Bedfordshire Hospitals NHS Foundation Trust disclosed that over 32,000 patient data records related to Synnovis tests were exfiltrated and took over a year to analyse what information was related to which patient. The breached data includes patient name and number, date of birth, postcode, and test results.
  • In H1 2026, Qilin averaged between seven and nine published UK victims per month. For the entries listing an estimated attack date, there was a roughly six-week extortion lifecycle on average, from initial intrusion to the date the victim is publicly named.
  • This UK footprint highlights their aggressive pursuit of Small-to-Medium Enterprises (SMEs) as most organisations had a revenue between £10m and £250m.
  • Interestingly, one of the Qilin victims, Salford City College, also appeared on both the Qilin and DragonForce Tor data leak site (DLS) only a few days apart from 6 March to 10 March 2026, respectively.

Qilin’s UK-based victims from H1 2026 spanned a diverse range of sectors:

  • Construction & Property Development
  • Manufacturing & Engineering
  • Legal & Professional Services
  • Technology & IT Infrastructure
  • Education
  • Healthcare

Analyst Comment 

Many of the organisations targeted by Qilin operators are just large enough to have the funds to pay mid-tier ransoms but often never got around to making an investment into a 24/7 dedicated threat detection service, such as an outsourced Security Operations Centre (SOC). Such services are usually enough protection to prevent an attack. If a ransomware affiliate faces tough resistance from a target, they often move on to a weaker and easier one.

One key face to also note about Tor data leak sites operated by ransomware groups is that they include victims who failed to pay the ransom. The total number of victims by each group is often going to be higher.

The reason for the cross-posting of Salford City College is unknown for now. However, it could indicate that an affiliate may be using both Qilin and DragonForce RaaS platforms. An alternative theory could be that the college was hit by two affiliates of each RaaS. Interestingly, cross-posting on multiple leak sites is not as uncommon as it seems. Some victims listed on the Qilin leak site have historically appeared on the leak sites of ALPHV/BlackCat and Conti as well.

The Ransomware Vulnerability Matrix Group Profile for Qilin reveals a diverse set of exploits leveraged by its operators. Like many other ransomware gangs, Qilin operators have exploited corporate VPN gateways such as Fortinet, Check Point, and WatchGuard for initial access. Interestingly, the exploitation of SmarterTools SmarterMail and SolarWinds Web Help Desk is less common but are also exploited by the Warlock ransomware gang. Another common theme from Qilin's Ransomware Tool Matrix Group Profile is their regular abuse of Bring Your Own Vulnerable Driver (BYOVD) tactics to bypass Endpoint Detection and Response (EDR) and Antivirus software.

Defensive Takeaways 

  • Harden Common Attack Paths: Treat any web-facing helpdesk or mail server as a high-risk device. If it does not absolutely require open internet access, place it behind a zero-trust network access gateway or a strict VPN. Enforce strict phishing-resistant Multi-Factor Authentication (MFA) on all remote access points. Ensure processes are in place for rapid patching and integrity checks for all corporate VPN gateways.
  • Overcoming SME Resource Caps: Organisations must bridge the gap with an outsourced MDR service. Ransomware execution routinely happens at 2:00 AM on Fridays and weekends. Outdated antivirus agents alone are not enough to stop a motivated human adversary.
  • Utilise Free Support Services: Capitalise on sovereign and community-vetted threat intelligence feeds to block attacker infrastructure early. UK defenders should actively enroll in the National Cyber Security Centre’s MyNCSC portal and integrate community resources like the Spamhaus DROP list and Abuse.ch tracking into their perimeter firewalls to automatically block known ransomware command-and-control (C2) nodes. ShadowServer and Team Cymru also offer useful free community resources.

Relevant Sources 

  1. https://www.bbc.co.uk/news/articles/c1d2wwyd6qqo
  2. https://www.bedfordshirehospitals.nhs.uk/news/notification-synnovis-cyber-incident/
  3. https://www.bleepingcomputer.com/news/security/qilin-ransomware-gang-linked-to-attack-on-london-hospitals/

Relevant CTI Sources

  1. https://www.ransomware.live/map/GB
  2. https://www.ransomware.live/group/qilin
  3. https://www.ransomware.live/id/c2FsZm9yZGNjLmFjLnVrQGRyYWdvbmZvcmNl
  4. https://www.ransomware.live/id/U2FsZm9yZCBDaXR5IENvbGxlZ2VAcWlsaW4
  5. https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/GroupProfiles/Qilin.md
  6. https://github.com/BushidoUK/Ransomware-Vulnerability-Matrix/blob/main/GroupProfiles/Qilin.md
  7. https://blog.bushidotoken.net/2024/06/tracking-adversaries-qilin-raas.html 
  8. https://www.bleepingcomputer.com/news/security/check-point-links-vpn-zero-day-attacks-to-qilin-ransomware-gang/

  • ✇@BushidoToken Threat Intel
  • UK Cybercrime Journal: Sustained DragonForce Campaign BushidoToken
     What HappenedThroughout May 2026, affiliates of the DragonForce ransomware-as-a-service (RaaS) platform claimed seven UK-based companies as its victims by posting them on their Tor data leak site.On 27 May 2026 alone, DragonForce ended the month by posting 22 victims from around the world, four of which were UK-based firms.DragonForce’s UK-based victims from May spanned a diverse range of industries:Professional Services & Talent: Practicus (interim management/executive search)Financial &am
     

UK Cybercrime Journal: Sustained DragonForce Campaign

17 de Junho de 2026, 05:00

 What Happened

  • Throughout May 2026, affiliates of the DragonForce ransomware-as-a-service (RaaS) platform claimed seven UK-based companies as its victims by posting them on their Tor data leak site.
  • On 27 May 2026 alone, DragonForce ended the month by posting 22 victims from around the world, four of which were UK-based firms.
DragonForce’s UK-based victims from May spanned a diverse range of industries:
  • Professional Services & Talent: Practicus (interim management/executive search)
  • Financial & Tax Services: WSM (UK tax advisory)
  • Infrastructure & Logistics: ERH (traffic management solutions) and Refreshment Systems (vending/logistics)
  • Heavy Industry/Construction: Arsenal Scaffold
  • Technology & IT: Helix International (managed enterprise software)
  • Luxury Retail/Finance: Cult Wines.


Analyst Comment

Active since late 2023, DragonForce remains a persistent cybercriminal threat particularly towards the UK. The recent flurry of disclosures on the DragonForce ransomware Tor data leak site in May highlights a highly active and accelerating threat campaign towards the UK. This diverse range of firms indicates that DragonForce affiliates are largely opportunistic rather than specific. They tend to exploit vulnerabilities or compromised credentials wherever they find them, rather than executing a highly tailored campaign against a single industry or target.


While these companies may not all be household names, some of them will be important suppliers and service providers for their local regions. Helix International in particular is a concern due to them being a managed service provider (MSP) that caters to medium, large, and Fortune 500 companies across various industries, including healthcare, finance, retail, and entertainment.


The Ransomware Vulnerability Matrix Group Profile for DragonForce shows that affiliates are highly adept at targeting edge devices and remote access points, such as Ivanti Connect Secure, Fortinet FortiOS, SonicWall SSL-VPN. A recurring theme across DragonForce's Ransomware Tool Matrix Group Profile is their regular abuse of Bring Your Own Vulnerable Driver (BYOVD) tactics to bypass Endpoint Detection and Response (EDR) and Antivirus software.


In June 2025, DragonForce made the news as it was used by affiliates, attributed to Scattered Spider, to attack the UK retailers M&S, Co-op, and Harrods in a string of high-profile attacks. More recently, DragonForce has reportedly been actively recruiting on English-speaking cybercrime forums.


Defensive Takeaways

  • Attack Surface Monitoring: Based on DragonForce’s reported tactics, organisations must review their RDP (Port 3389) exposures as well as any unpatched SSL-VPNs. Prevent these exposures and apply updates as soon as possible. Any brief exposures or time when systems are left unpatched leaves an open window for the adversary to get inside.
  • Rotate your credentials & implement MFA: It may sound simple, but a lot of these DragonForce incidents have been because of RDP and SSL-VPN account brute forcing. Therefore, the importance of using strong credentials, secure password managers, and multi-factor authentication (MFA) enabled cannot be overstated. 
  • Back Your Data Up: To increase your odds of recovering from a ransomware attack, it’s essential to maintain backups of your business critical data. However, as the DragonForce affiliates are known to target backup solutions like Veeam servers, it’s increasingly important to maintain regularly updated offline backups to be able to restore from.


Relevant Sources

  1. https://www.ransomware.live/group/dragonforce
  2. https://www.ransomware.live/map/GB
  3. https://x.com/falconfeedsio/status/2060220753400967490


Relevant CTI Resources

  1. https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/GroupProfiles/DragonForce.md
  2. https://github.com/BushidoUK/Ransomware-Vulnerability-Matrix/blob/main/GroupProfiles/DragonForce.md
  3. https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/CommunityReports/CR-021-DRAGONFORCE-APR-2025.md
  4. https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/CommunityReports/CR-022-DRAGONFORCE-FEB-2026.md
  5. https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/CommunityReports/CR-023-DRAGONFORCE-AUG-2024.md

  • ✇@BushidoToken Threat Intel
  • Ransomware Tool Matrix Project Updates: Three Groups To Track BushidoToken
     IntroductionThis blog is a focused update on the latest updates to the Ransomware Tool Matrix (RTM) and the Ransomware Vulnerability Matrix (RVM) covering three groups that I have published profiles for to help defenders home in on the threats most relevant to them: TheGentlemen, DragonForce, and WarLock.Rather than write another broad ecosystem summary, the goal of this post is to introduce these profiles, briefly explain why each group matters right now, and give readers direct links to them
     

Ransomware Tool Matrix Project Updates: Three Groups To Track

15 de Junho de 2026, 05:31

 


Introduction


This blog is a focused update on the latest updates to the Ransomware Tool Matrix (RTM) and the Ransomware Vulnerability Matrix (RVM) covering three groups that I have published profiles for to help defenders home in on the threats most relevant to them: TheGentlemen, DragonForce, and WarLock.


Rather than write another broad ecosystem summary, the goal of this post is to introduce these profiles, briefly explain why each group matters right now, and give readers direct links to them so defenders can pivot straight into hunting, detection engineering, and patch prioritisation.


For anyone new to the projects, please read the descriptions on GitHub or feel free to watch my talk explaining the project at BSides London.


Why these three groups?


Each of the three groups added in this update represents a different slice of the current ransomware ecosystem:


TheGentlemen


TheGentlemen is a newer operation that has matured quickly, with a large and varied toolkit that reflects how cross-pollinated the affiliate ecosystem has become. The recent internal chat leak gave researchers a rare look into their tradecraft, and the profiles capture both the tooling and the exploited CVEs that have been observed across multiple intrusions. TheGentlemen’s RTM profile is here and RVM profile is here.


DragonForce


DragonForce has continued to escalate throughout 2025 and into 2026, branching into MSP-focused attacks and standing up its own "cartel" model that other affiliates can plug into. Its exploitation of edge devices (Ivanti, Fortinet, SonicWall) and SimpleHelp RMM make it a high-priority threat for any organisation using such systems. DragonForce’s RTM profile is here and RVM profile is here.


WarLock


WarLock jumped onto everyone's radar after the ToolShell SharePoint zero-day exploitation campaign, and has since been linked to a string of edge-application exploits including SmarterMail, SolarWinds Web Help Desk, and Gladinet CentreStack. It is a strong example of a likely China-based operator that lives on zero-day exploitation of internet-facing software. WarLock’s RTM profile is here and RVM profile is here.


Observations and Trends


A few themes are worth flagging across all three profiles:


  • BYOVD is now standard, not novel. All three groups have been observed bringing vulnerable drivers to disable or blind EDR. TheGentlemen with ThrottleStop driver, DragonForce with the TrueSight and Hangzhou Shunwang drivers, and WarLock with Antiy, NsecSoft, Rising, and VMTools drivers. If your detection stack is not yet hunting on or blocking suspicious driver loads and known-bad driver hashes, that is a high-priority gap to close.
  • Network edge devices and other internet-facing systems remain the front door to victim networks for these groups. Fortinet, Ivanti, SonicWall, SimpleHelp, Microsoft SharePoint, SmarterMail, SolarWinds Web Help Desk, and Gladinet CentreStack all appear across these three profiles. Patch prioritisation that focuses on internet-exposed appliances and admin tooling continues to give defenders a valuable return on effort.
  • Legitimate tooling continues to blur the line. Velociraptor, Cloudflared, VSCode Tunnels, AnyDesk, MeshCentral, FreeRDP, PuTTY, OpenSSH, and a long list of legitimate cloud services are all being repurposed for ransomware operations. Defender should use these lists to begin baselining what should exist in their environment and start alerting on the rest.

Conclusion


My recommendation for defenders remains the same as in previous updates: take the tools and CVEs from the RTM and RVM profiles and start threat hunting for their presence, writing detection rules to alert on certain behaviours, and blocking what is not expected or permitted in your environment. These three new profiles should make that easier to scope by group when you need to brief leadership, prioritise a hunt, or map your exposure to a specific campaign.


Here's a few sites that can help with turning the threat intel in these new profiles into detections:


- https://rulehound.com/rules

- https://detection.fyi

- https://www.snapattack.com/community


As always, feedback and pull requests are very welcome on both repos. Thanks to everyone who has contributed reports, corrections, and ideas. These projects only stay useful because the community keeps feeding them one way or another.

  • ✇The DFIR Report
  • Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs editor
    Key Takeaways Private Threat Briefs: 20+ private DFIR reports annually. Contact us today for pricing or a demo! Table of Contents: Case Summary Analysts Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact Timeline Diamond Model Indicators Detections MITRE ATT&CK Case Summary The intrusion began in […] The post Blurring the Lines: Intrusion Shows Connection With Three Major Ra
     

Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs

Por:editor
8 de Setembro de 2025, 11:20

Key Takeaways Private Threat Briefs: 20+ private DFIR reports annually. Contact us today for pricing or a demo! Table of Contents: Case Summary Analysts Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact Timeline Diamond Model Indicators Detections MITRE ATT&CK Case Summary The intrusion began in […]

The post Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs appeared first on The DFIR Report.

❌
❌