• News/
  • https://www.bleepingcomputer.com/news/security/deep-dive-into-dragonforce-ransomware-and-its-scattered-spider-connection/

Deep dive into DragonForce ransomware and its Scattered Spider connection

BleepingComputer
·
Sponsored by Acronis
·
Published Dec 3, 2025
·
Updated

Security researchers have conducted an in-depth analysis of DragonForce ransomware that initially emerged in 2023 and has since evolved into what it calls a "ransomware cartel." The most recent variant exploits susceptible drivers such as truesight.sys and rentdrv2.sys to deactivate security programs, shut down protected processes and fix encryption vulnerabilities that were earlier linked to Akira ransomware. The updated encryption scheme addresses vulnerabilities that were openly documented in a Habr publication referenced on DragonForce's leak website. DragonForce has intensified its operations against organizations worldwide, publishing details of more compromised entities than in the previous year. The group's most prominent breach, involving retail company Marks & Spencer, was carried out in partnership with the cybercriminal collective Scattered Spider hacking group. DragonForce operates as a ransomware-as-a-service (RaaS) operation. The group reignited ransomware activities, and has been actively recruiting nefarious collaborators through underground cybercrime platforms. At the start, the gang used the compromised LockBit 3.0 builder to create its encryption tools and later transitioned to a modified version of Conti v3 source code.

Returning in 2025, DragonForce rebranded itself as a “ransomware cartel,” marking a sudden shift in operational strategy. By offering affiliates 80% of profits, customizable encryptors and infrastructure, DragonForce lowers the barrier ...

Read full article

Affected Software

2 affected components
Unknown truesight.sys
Unknown rentdrv2.sys
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article explores the DragonForce ransomware and its connection to a group known as Scattered Spider.

2

What security implications are discussed regarding DragonForce ransomware?

The article discusses the evolution of DragonForce into a 'ransomware cartel' and its method of exploiting vulnerable drivers.

3

What products or software are affected by this ransomware?

The affected software includes truesight.sys and rentdrv2.sys, both of which are associated with the ransomware's recent variants.

4

When did DragonForce ransomware first emerge?

DragonForce ransomware initially emerged in 2023.

5

What unique element does DragonForce ransomware incorporate in its operations?

DragonForce ransomware operates similarly to a cartel, indicating organized and collaborative ransomware activities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203