Visualização de leitura
Ransom & Dark Web Issues Week 2, August 2026
UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026
What Happened
- Throughout H1 2026, the Qilin ransomware-as-a-service (RaaS) Tor data leak site (DLS) listed the most UK-based victims out of all ransomware gangs, with up to 37 British organisations hit in total. Qilin's victim count is followed by DragonForce with 21 victims listed, and TheGentlemen with 18 listed.
- The fallout from the Qilin attack on the UK National Health Service (NHS) supplier, Synnovis, in 2024 persists as well. On 1 June 2026, the Bedfordshire Hospitals NHS Foundation Trust disclosed that over 32,000 patient data records related to Synnovis tests were exfiltrated and took over a year to analyse what information was related to which patient. The breached data includes patient name and number, date of birth, postcode, and test results.
- In H1 2026, Qilin averaged between seven and nine published UK victims per month. For the entries listing an estimated attack date, there was a roughly six-week extortion lifecycle on average, from initial intrusion to the date the victim is publicly named.
- This UK footprint highlights their aggressive pursuit of Small-to-Medium Enterprises (SMEs) as most organisations had a revenue between £10m and £250m.
- Interestingly, one of the Qilin victims, Salford City College, also appeared on both the Qilin and DragonForce Tor data leak site (DLS) only a few days apart from 6 March to 10 March 2026, respectively.
Qilin’s UK-based victims from H1 2026 spanned a diverse range of sectors:
- Construction & Property Development
- Manufacturing & Engineering
- Legal & Professional Services
- Technology & IT Infrastructure
- Education
- Healthcare
Analyst Comment
Many of the organisations targeted by Qilin operators are just large enough to have the funds to pay mid-tier ransoms but often never got around to making an investment into a 24/7 dedicated threat detection service, such as an outsourced Security Operations Centre (SOC). Such services are usually enough protection to prevent an attack. If a ransomware affiliate faces tough resistance from a target, they often move on to a weaker and easier one.
One key face to also note about Tor data leak sites operated by ransomware groups is that they include victims who failed to pay the ransom. The total number of victims by each group is often going to be higher.
The reason for the cross-posting of Salford City College is unknown for now. However, it could indicate that an affiliate may be using both Qilin and DragonForce RaaS platforms. An alternative theory could be that the college was hit by two affiliates of each RaaS. Interestingly, cross-posting on multiple leak sites is not as uncommon as it seems. Some victims listed on the Qilin leak site have historically appeared on the leak sites of ALPHV/BlackCat and Conti as well.
The Ransomware Vulnerability Matrix Group Profile for Qilin reveals a diverse set of exploits leveraged by its operators. Like many other ransomware gangs, Qilin operators have exploited corporate VPN gateways such as Fortinet, Check Point, and WatchGuard for initial access. Interestingly, the exploitation of SmarterTools SmarterMail and SolarWinds Web Help Desk is less common but are also exploited by the Warlock ransomware gang. Another common theme from Qilin's Ransomware Tool Matrix Group Profile is their regular abuse of Bring Your Own Vulnerable Driver (BYOVD) tactics to bypass Endpoint Detection and Response (EDR) and Antivirus software.
Defensive Takeaways
- Harden Common Attack Paths: Treat any web-facing helpdesk or mail server as a high-risk device. If it does not absolutely require open internet access, place it behind a zero-trust network access gateway or a strict VPN. Enforce strict phishing-resistant Multi-Factor Authentication (MFA) on all remote access points. Ensure processes are in place for rapid patching and integrity checks for all corporate VPN gateways.
- Overcoming SME Resource Caps: Organisations must bridge the gap with an outsourced MDR service. Ransomware execution routinely happens at 2:00 AM on Fridays and weekends. Outdated antivirus agents alone are not enough to stop a motivated human adversary.
- Utilise Free Support Services: Capitalise on sovereign and community-vetted threat intelligence feeds to block attacker infrastructure early. UK defenders should actively enroll in the National Cyber Security Centre’s MyNCSC portal and integrate community resources like the Spamhaus DROP list and Abuse.ch tracking into their perimeter firewalls to automatically block known ransomware command-and-control (C2) nodes. ShadowServer and Team Cymru also offer useful free community resources.
Relevant Sources
- https://www.bbc.co.uk/news/articles/c1d2wwyd6qqo
- https://www.bedfordshirehospitals.nhs.uk/news/notification-synnovis-cyber-incident/
- https://www.bleepingcomputer.com/news/security/qilin-ransomware-gang-linked-to-attack-on-london-hospitals/
Relevant CTI Sources
- https://www.ransomware.live/map/GB
- https://www.ransomware.live/group/qilin
- https://www.ransomware.live/id/c2FsZm9yZGNjLmFjLnVrQGRyYWdvbmZvcmNl
- https://www.ransomware.live/id/U2FsZm9yZCBDaXR5IENvbGxlZ2VAcWlsaW4
- https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/GroupProfiles/Qilin.md
- https://github.com/BushidoUK/Ransomware-Vulnerability-Matrix/blob/main/GroupProfiles/Qilin.md
- https://blog.bushidotoken.net/2024/06/tracking-adversaries-qilin-raas.html
- https://www.bleepingcomputer.com/news/security/check-point-links-vpn-zero-day-attacks-to-qilin-ransomware-gang/
An analysis of incidents at Brazilian educational institutions

Introduction
Because of the amount of data that can be obtained and the high impact that successful attacks may have, educational institutions are frequent targets of cybercriminals. Both public and private schools and universities rely on software for managing personally identifiable information (PII) that is often insecure or insufficiently tested against known vulnerabilities. In addition, machines used by multiple people without accountability can be vulnerable to insider threats.
The complexity of academic environments amplifies this risk. Unlike corporate networks, educational institutions have to provide a network that supports students, professors, researchers, administrative staff, third-party contractors, and visitors. Each of these groups has different security requirements and access control levels, making it difficult to enforce consistent security policies. A security breach can have severe consequences since it may expose vast amounts of sensitive information, such as social security numbers (CPF in Brazil), addresses, phone numbers, and even parents’ names. Armed with this information, attackers can attempt phishing attacks and impersonate the victims in SIM swapping attacks, a common practice in Brazil.
In this article, we provide details about attacks on educational institutions in Brazil observed by our Global Emergency Response Team (GERT) since 2025. We share general statistics, common threats, initial access vectors, and the impact of such violations. Additionally, we present some interesting cases encountered by our team and the identified TTPs. Finally, we offer recommendations to help institutions protect themselves against future attacks.
Key findings and statistics
Our dataset encompasses incident response cases from January 2025 to June 2026. As the chart below shows, the majority of attacks targeted institutions in São Paulo state, Brazil’s most populous state and a significant center of economic and financial activity. We also had cases in Rio de Janeiro and Pernambuco.
Geographical distribution of incident response requests at educational institutions (download)
Of the customers who requested incident response, 60% were private institutions and 40% were public institutions.
Private and public institutions (download)
The most frequent reasons for requesting IR services were related to suspicious endpoint activities, encrypted files, and the presence of suspicious files.
Incident response request reasons (download)
High-severity incidents accounted for 40% of the total cases, while the remaining 60% were medium severity.
Distribution of incidents by severity (download)
The high-severity incidents were mainly related to ransomware attacks. Interestingly, private institutions were the most targeted by ransomware, while incidents in public institutions were mostly related to suspicious endpoint activity and privilege escalation attempts. The most common ransomware families found in our dataset were DragonForce and LockBit 3, whose builder was leaked back in 2022. By using the leaked LockBit builder with a valid privileged account, attackers can build variants capable of disabling defenses and erasing logs.
The most common initial access vectors included the use of valid accounts, exploitation of public-facing applications, and insiders.
Initial access vectors (download)
For privilege escalation, the attackers often relied on Potato variants (GodPotato, SweetPotato, and BadPotato).
We also observed attackers using tools like AnyDesk for remote access, PsExec for lateral movement within compromised infrastructures, and AV-killer malware to terminate the system’s defenses. The latter was mainly used in ransomware-related incidents.
These data reveal an interesting pattern in the threat landscape affecting educational institutions in the region. Many incidents were not caused by highly sophisticated techniques but rather by the abuse of common weaknesses such as valid accounts, exposed applications, and inadequate patch management, as well as the use of publicly available tools that are well-known to the adversaries. The prevalence of ransomware in private institutions suggests a stronger financial motivation, likely because attackers assume these organizations are more capable of paying for data recovery than public schools and universities.
Most attacks were discovered promptly and lasted from a few minutes to a couple of hours. However, technical incident response activities averaged 9.6 hours. This indicates that the impact caused by an incident often extends beyond the timeframe of the active attack, requiring extensive triage and analysis by the forensic investigators to fully restore operations.
One interesting fact is that we are still observing the use of Windows 10 in the infrastructures of educational institutions, even after Microsoft’s official end-of-support date of October 2025. In addition, we found that some customer organizations were using Windows Server 2016 without security patches and fixes. Using outdated and unsupported operating systems increases the attack surface of an infrastructure because attackers can exploit publicly available vulnerabilities to access vulnerable systems and expand their presence in the network. In addition, legacy operating systems may be incompatible with modern evidence collection tools, necessitating extra time and alternative procedures for forensic acquisition.
Obsolete systems in organizations (download)
Interesting cases
Case 01 – Leaked LockBit builder
In one case, we identified the use of a custom version of LockBit that was generated using the leaked builder. The ransomware was delivered to the organization’s infrastructure via a valid account that had been leaked. It encrypted the organization’s internal systems, including file servers and databases that stored student profiles and other data. There was no evidence of data exfiltration from the affected machines.
During our analysis of the LockBit sample, we were able to extract its configuration. Interestingly, it was configured without the impersonation and spreading options. This meant the attacker had to perform manual lateral movement to deploy the malware across the network.
"config": {
"settings": {
"impersonation": false,
"local_disks": true,
"network_shares": true,
"kill_processes": true,
"kill_services": true,
"set_wallpaper": true,
"self_destruct": true,
"kill_defender": true,
"wipe_freespace": true,
"psexec_netspread": false,
"gpo_netspread": false,
…Further analysis revealed that the attacker used PsExec for lateral movement. By analyzing the Update Sequence Number (USN) Journal, we were able to identify .KEY files associated with PsExec that showed us the previously compromised machines used by the attacker.
After gaining access to the target machines, the adversaries deployed a batch script to disable the system’s defenses. Our analysis of this artifact showed that they had the administrative credentials to disable the EDR in place. In addition, the script enabled RDP, which gave the attackers remote access to the target. The listing below shows an excerpt of the script:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f
netsh advfirewall firewall add rule name="allow RemoteDesktop" dir=in protocol=TCP localport=3389 action=allow
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableRealtimeMonitoring /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableBehaviorMonitoring /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableOnRealTimeProtection /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableIOAVProtection /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableScriptScanning /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SpyNetReporting /t REG_DWORD /d 0 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SubmitSamplesConsent /t REG_DWORD /d 2 /f
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "SecurityHealth" /t REG_SZ /d "" /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\{UUID}" /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v ServiceKeepAlive /t REG_DWORD /d 0 /f
sc stop WinDefend
sc config WinDefend start= disabledFinally, by cross-checking the Prefetch files, we were able to identify the precise dates of PsExecSvc.exe and LBB.exe (LockBit) execution. This revealed that the attacker established the initial connection to the analyzed machine around 5:30am UTC and ran LBB.exe for the last time at 10am UTC on the same day, resulting in an activity window of approximately four hours and thirty minutes. We were able to identify the extent of the compromise and the additional machines that required network isolation for further forensic analysis, containment, and remediation.
Case 02 – DragonForce deployed via AnyDesk
In another incident, we identified a compromised user account that the adversaries used to install the AnyDesk software to enable remote access. Although the attacker erased the system logs after encrypting the victim’s files, we were able to identify the ransomware execution event via the Prefetch and Amcache.hve files, which provided us with the SHA-1 hash of the sample.
Once we obtained the SHA-1 of the malicious artifact (named by the attacker as 1.EXE), we were able to confirm that it was a DragonForce variant. Even though the lack of evidence made the analysis more difficult, this case shows that forensic investigators must be prepared to identify information that the attackers missed or left untouched.
Case 03 – Python keylogger used by an insider
The third incident illustrates how a series of bad practices enabled an insider to collect passwords from other users inside the infrastructure. First, the customer contacted us stating that a machine was exhibiting strange behavior: files containing passwords were being created. We started with triage collection on one of the affected machines.
Evidence from the Program Compatibility Assistant (PCA) showed the execution of two suspicious files, Windows Host Widgets.exe and Windows Host Widgets_.exe, both located in the C:\Users\<user>\.vscode\dlo directory, where <user> represents a user account shared by everyone who uses the machine. The same artifacts were identified within the Amcache.hve file, and multiple executions were also confirmed by analyzing the Prefetch files. Another interesting source of evidence, UserAssist, confirmed that the threat actor also executed both EXE files by double-clicking on them.
MFT analysis showed that multiple log files named cacheX.txt were created in the previously mentioned directory, where X was a number that increased with each malware execution. We then analyzed the EXE files to confirm their behavior. Luckily, both proved to be the same Python script, which we could easily decompile.
As shown in the listing below, the script contains methods and strings with Portuguese names. It is capable of hiding the log files from view in Explorer. The developer also set a procedure to identify when the Caps Lock key was pressed, in order to record the correct passwords.
def get_base_path():
...
def encontrar_proximo_nome(base='cache'):
...
def set_file_hidden(filepath):
...
ctypes.windll.kernel32.SetFileAttributesW(str(filepath), FILE_ATTRIBUTE_HIDDEN)
...
with open(log_file, 'a', encoding='utf-8') as f:
f.write(f'\n\n--- Registro iniciado em {datetime.datetime.now()} ---\n')
set_file_hidden(log_file)
...
def is_capslock_on():
return bool(ctypes.windll.user32.GetKeyState(20) & 1)
...
def on_press(key):
...
def on_release(key):
...
def main():
with keyboard.Listener(on_press=on_press, on_release=on_release) as listener:
listener.join()
if __name__ == '__main__':
main()This simple script did not implement any persistence or automated data exfiltration mechanisms. Therefore, the insider likely had to manually retrieve the generated log files containing the text typed by the victims. By revisiting the previously collected evidence, we identified USB connections around the same time as the script’s executions. This suggests that removable media was probably used to collect the generated keylogging logs from the environment. As a result of the investigation, the customer changed the passwords of all affected accounts. However, without additional evidence or footage, it was not possible to conclusively attribute the activities to a specific individual and take the appropriate disciplinary and legal measures.
Conclusions and recommendations
The incidents highlighted in this article demonstrate that Brazilian educational institutions face a diverse set of threats, ranging from ransomware operations to insider activity. In many cases, the attackers relied on valid credentials, exposed services, remote access tools, poor patch management, and insufficient endpoint hardening rather than advanced malware or new techniques. Based on these findings, educational institutions should prioritize controls that reduce the likelihood of account compromise and the impact of ransomware deployment. They should also improve forensic visibility after an incident.
Institutions should enforce the use of multi-factor authentication (MFA) for all publicly accessible services, especially VPNs, remote access portals, and email accounts. Since valid accounts were one of the most common initial access vectors observed in our dataset, MFA can significantly reduce the likelihood that stolen or reused credentials alone will compromise the entire environment. We also recommend periodically reviewing privileged accounts, removing unnecessary administrative permissions, and avoiding shared accounts, especially on machines accessed by multiple users, since this makes accountability extremely difficult.
Each user should have their own account, following the principle of least privilege to prevent unauthorized software execution. Additionally, it is advisable to restrict and monitor the use of remote access tools such as AnyDesk or TeamViewer. Unexpected installations or executions of these tools should be treated as high-priority alerts.
To minimize the impact of ransomware, educational institutions should improve their backup and recovery strategy. Backups should be isolated from the primary environment (preferably in more than one location) and tested regularly. Centralized logging, extended EDR telemetry retention, and proper time synchronization across hosts can also improve the ability to reconstruct an attack timeline and implement the necessary response measures.
The use of outdated systems increases the attack surface, so we recommend that organizations adopt an effective update and patch management policy. It is also important to raise security awareness, since users must understand the risks associated with credential sharing, unknown executables, and unauthorized software.
From a digital forensics and incident response (DFIR) perspective, the reviewed incidents demonstrate that effective incident response activities require correlating multiple forensic artifacts in order to reconstruct the attacker’s actions. Investigators should be aware of how to find information even when logs are missing. Many other artifacts are preserved and can be used for this purpose, such as Amcache, PCA, Prefetch, UserAssist, MFT, and USN Journal. The attackers may fail to erase all traces of their activity, so taking a broad forensic approach is of the utmost importance for determining the scope of the compromise and supporting containment and remediation actions.
Observed TTPs
The table below shows the observed TTPs in our dataset, including cases not detailed in this post.
| Tactic | Technique | ID |
| Resource Development | Compromise Accounts | T1586 |
| Collection | Input Capture: Keylogging | T1056.001 |
| Execution | System Services: Service Execution | T1569.002 |
| Execution | Hijack Execution Flow: DLL | T1574.001 |
| Privilege Escalation | Exploitation for Privilege Escalation | T1068 |
| Lateral Movement | Remote Services: Remote Desktop Protocol | T1021.001 |
| Command and Control | Remote Access Tools | T1219 |
| Exfiltration | Exfiltration over Physical Medium: Exfiltration over USB | T1052.001 |
| Impact | Data Encrypted for Impact | T1486 |




June 2026 Ransomware Trend Report
Ransom & Dark Web Issues Week 3, July 2026
May 2026 Threat Trend Report on Ransomware
DragonForce Hid Inside Microsoft Teams and Nobody Noticed for Two Months
DragonForce hid for months by routing malware traffic through Microsoft Teams infrastructure, masking C2 activity and evading network detection.
DragonForce ransomware operators hit a major U.S. services firm and stayed hidden for one to two months by routing their command-and-control traffic through Microsoft’s own Teams relay servers. Symantec’s threat hunters tracked the custom backdoor they used as Backdoor.Turn. To any defender watching the network, the traffic looked like normal Teams activity.
“Backdoor.Turn obtains an anonymous Teams visitor token from Microsoft’s Skype-backed identity services, uses a legitimate Microsoft TURN relay to set up the connection, and then runs a QUIC session to the attacker’s real command-and-control server.” reads the report published by Symantec. “To our knowledge this is the first time TURN relay infrastructure has been abused this way in the wild. It is relatively unusual to see ransomware attackers using their own custom tools, and it is particularly unusual to see them using a custom tool as sophisticated as Backdoor.Turn.
This is the first known malware to abuse TURN relay infrastructure this way. The technique was inspired by the Ghost Calls method presented at Black Hat in 2025, which focused on C&C communication that’s hard to profile from the network side.
The backdoor is written in Go and injected into the legitimate DbgView64.exe process. The malicious payload can execute commands, scan networks, map Active Directory, move laterally with stolen credentials, and pull passwords from browsers.
The attackers got in through what appears to be a vulnerability in an SQL or MSSQL server, though the exact flaw is still unknown. They may have bought access from a broker. Once inside, starting December 2025, they dropped a .zip archive containing a legitimate VirtualBox executable paired with a malicious DLL designed to sideload and fetch additional payloads from remote servers.
For defense evasion, they used the Bring Your Own Vulnerable Driver (BYOVD) technique against multiple signed drivers, including a novel attack on Huawei’s HWAuidoOs2Ec.sys. That driver’s vulnerable status had been documented by Huntress in March 2026, after this attack already happened.
“This driver wasn’t known to be exploited like this in the wild prior to this attack, though its vulnerable status was documented by researchers at Huntress in March 2026, after this attack happened.” states the report.
They also deployed a custom-built malicious driver disguised as a legitimate Palo Alto driver, which doesn’t even fit the standard BYOVD definition since it wasn’t a legitimate driver to begin with.
DragonForce has been active since at least June 2023 and has since moved from a standard ransomware-as-a-service model to a cartel structure. Backdoor.Turn gets installed after the ransomware runs, which suggests the group is either maintaining persistence for a follow-up intrusion or selling access to other attackers.
“The attackers in this campaign use exceptionally sophisticated cyber tradecraft. The configuration of Backdoor.Turn means that security products only see C&C traffic going to legitimate Teams servers, leaving defenders unaware that data is being siphoned away by malicious actors.” concludes the report. “The exploitation of a driver that was not at the time known to be vulnerable (Havoc Process Terminator) also demonstrates a strong level of expertise and sophistication on behalf of the attackers.”
DragonForce has been active since at least 2023. The cybercrime group has evolved from a traditional ransomware-as-a-service operation into a structured cybercrime cartel. According to Symantec, the group has steadily expanded its capabilities, adopting advanced techniques such as the Backdoor.Turn malware and sophisticated BYOVD evasion methods. Its growing operational maturity, resources, and focus on targeted attacks position DragonForce among today’s most capable and persistent ransomware threats. (315 characters)
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
DragonForce Ransomware Abused Microsoft Teams to Hide Malware Activity
UK Cybercrime Journal: Sustained DragonForce Campaign
What Happened
- Throughout May 2026, affiliates of the DragonForce ransomware-as-a-service (RaaS) platform claimed seven UK-based companies as its victims by posting them on their Tor data leak site.
- On 27 May 2026 alone, DragonForce ended the month by posting 22 victims from around the world, four of which were UK-based firms.
- Professional Services & Talent: Practicus (interim management/executive search)
- Financial & Tax Services: WSM (UK tax advisory)
- Infrastructure & Logistics: ERH (traffic management solutions) and Refreshment Systems (vending/logistics)
- Heavy Industry/Construction: Arsenal Scaffold
- Technology & IT: Helix International (managed enterprise software)
- Luxury Retail/Finance: Cult Wines.
Analyst Comment
Active since late 2023, DragonForce remains a persistent cybercriminal threat particularly towards the UK. The recent flurry of disclosures on the DragonForce ransomware Tor data leak site in May highlights a highly active and accelerating threat campaign towards the UK. This diverse range of firms indicates that DragonForce affiliates are largely opportunistic rather than specific. They tend to exploit vulnerabilities or compromised credentials wherever they find them, rather than executing a highly tailored campaign against a single industry or target.
While these companies may not all be household names, some of them will be important suppliers and service providers for their local regions. Helix International in particular is a concern due to them being a managed service provider (MSP) that caters to medium, large, and Fortune 500 companies across various industries, including healthcare, finance, retail, and entertainment.
The Ransomware Vulnerability Matrix Group Profile for DragonForce shows that affiliates are highly adept at targeting edge devices and remote access points, such as Ivanti Connect Secure, Fortinet FortiOS, SonicWall SSL-VPN. A recurring theme across DragonForce's Ransomware Tool Matrix Group Profile is their regular abuse of Bring Your Own Vulnerable Driver (BYOVD) tactics to bypass Endpoint Detection and Response (EDR) and Antivirus software.
In June 2025, DragonForce made the news as it was used by affiliates, attributed to Scattered Spider, to attack the UK retailers M&S, Co-op, and Harrods in a string of high-profile attacks. More recently, DragonForce has reportedly been actively recruiting on English-speaking cybercrime forums.
Defensive Takeaways
- Attack Surface Monitoring: Based on DragonForce’s reported tactics, organisations must review their RDP (Port 3389) exposures as well as any unpatched SSL-VPNs. Prevent these exposures and apply updates as soon as possible. Any brief exposures or time when systems are left unpatched leaves an open window for the adversary to get inside.
- Rotate your credentials & implement MFA: It may sound simple, but a lot of these DragonForce incidents have been because of RDP and SSL-VPN account brute forcing. Therefore, the importance of using strong credentials, secure password managers, and multi-factor authentication (MFA) enabled cannot be overstated.
- Back Your Data Up: To increase your odds of recovering from a ransomware attack, it’s essential to maintain backups of your business critical data. However, as the DragonForce affiliates are known to target backup solutions like Veeam servers, it’s increasingly important to maintain regularly updated offline backups to be able to restore from.
Relevant Sources
- https://www.ransomware.live/group/dragonforce
- https://www.ransomware.live/map/GB
- https://x.com/falconfeedsio/status/2060220753400967490
Relevant CTI Resources
- https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/GroupProfiles/DragonForce.md
- https://github.com/BushidoUK/Ransomware-Vulnerability-Matrix/blob/main/GroupProfiles/DragonForce.md
- https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/CommunityReports/CR-021-DRAGONFORCE-APR-2025.md
- https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/CommunityReports/CR-022-DRAGONFORCE-FEB-2026.md
- https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/CommunityReports/CR-023-DRAGONFORCE-AUG-2024.md
Ransomware Tool Matrix Project Updates: Three Groups To Track
Introduction
This blog is a focused update on the latest updates to the Ransomware Tool Matrix (RTM) and the Ransomware Vulnerability Matrix (RVM) covering three groups that I have published profiles for to help defenders home in on the threats most relevant to them: TheGentlemen, DragonForce, and WarLock.
Rather than write another broad ecosystem summary, the goal of this post is to introduce these profiles, briefly explain why each group matters right now, and give readers direct links to them so defenders can pivot straight into hunting, detection engineering, and patch prioritisation.
For anyone new to the projects, please read the descriptions on GitHub or feel free to watch my talk explaining the project at BSides London.
Why these three groups?
Each of the three groups added in this update represents a different slice of the current ransomware ecosystem:
TheGentlemen
TheGentlemen is a newer operation that has matured quickly, with a large and varied toolkit that reflects how cross-pollinated the affiliate ecosystem has become. The recent internal chat leak gave researchers a rare look into their tradecraft, and the profiles capture both the tooling and the exploited CVEs that have been observed across multiple intrusions. TheGentlemen’s RTM profile is here and RVM profile is here.
DragonForce
DragonForce has continued to escalate throughout 2025 and into 2026, branching into MSP-focused attacks and standing up its own "cartel" model that other affiliates can plug into. Its exploitation of edge devices (Ivanti, Fortinet, SonicWall) and SimpleHelp RMM make it a high-priority threat for any organisation using such systems. DragonForce’s RTM profile is here and RVM profile is here.
WarLock
WarLock jumped onto everyone's radar after the ToolShell SharePoint zero-day exploitation campaign, and has since been linked to a string of edge-application exploits including SmarterMail, SolarWinds Web Help Desk, and Gladinet CentreStack. It is a strong example of a likely China-based operator that lives on zero-day exploitation of internet-facing software. WarLock’s RTM profile is here and RVM profile is here.
Observations and Trends
A few themes are worth flagging across all three profiles:
- BYOVD is now standard, not novel. All three groups have been observed bringing vulnerable drivers to disable or blind EDR. TheGentlemen with ThrottleStop driver, DragonForce with the TrueSight and Hangzhou Shunwang drivers, and WarLock with Antiy, NsecSoft, Rising, and VMTools drivers. If your detection stack is not yet hunting on or blocking suspicious driver loads and known-bad driver hashes, that is a high-priority gap to close.
- Network edge devices and other internet-facing systems remain the front door to victim networks for these groups. Fortinet, Ivanti, SonicWall, SimpleHelp, Microsoft SharePoint, SmarterMail, SolarWinds Web Help Desk, and Gladinet CentreStack all appear across these three profiles. Patch prioritisation that focuses on internet-exposed appliances and admin tooling continues to give defenders a valuable return on effort.
- Legitimate tooling continues to blur the line. Velociraptor, Cloudflared, VSCode Tunnels, AnyDesk, MeshCentral, FreeRDP, PuTTY, OpenSSH, and a long list of legitimate cloud services are all being repurposed for ransomware operations. Defender should use these lists to begin baselining what should exist in their environment and start alerting on the rest.
Conclusion
My recommendation for defenders remains the same as in previous updates: take the tools and CVEs from the RTM and RVM profiles and start threat hunting for their presence, writing detection rules to alert on certain behaviours, and blocking what is not expected or permitted in your environment. These three new profiles should make that easier to scope by group when you need to brief leadership, prioritise a hunt, or map your exposure to a specific campaign.
Here's a few sites that can help with turning the threat intel in these new profiles into detections:
- https://www.snapattack.com/community
As always, feedback and pull requests are very welcome on both repos. Thanks to everyone who has contributed reports, corrections, and ideas. These projects only stay useful because the community keeps feeding them one way or another.
May 2026 Dark Web Issue Trend Report
March 2026 Ransomware Trends Report
Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs
Key Takeaways Private Threat Briefs: 20+ private DFIR reports annually. Contact us today for pricing or a demo! Table of Contents: Case Summary Analysts Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact Timeline Diamond Model Indicators Detections MITRE ATT&CK Case Summary The intrusion began in […]
The post Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs appeared first on The DFIR Report.



