Threat Actor ๐ฒ๐พ Malaysia
DragonForce
DragonForce is a hacktivist group based in Malaysia that has been involved in cyberattacks targeting government institutions and commercial organizations in India. They have also targeted websites affiliated with Israel and have shown support for pro-Palestinian causes. The group has been observed using defacement attacks, distributed denial-of-service attacks, and data leaks as part of their campaigns. DragonForce Malaysia has demonstrated an ability to adapt and evolve their tactics over time.
Indicators of Compromise 5
MITRE ATT&CK TTPs 35
T1021.001 T1021.003 T1053 T1055 T1056.001 T1059.001 T1071.001 T1071.004 T1078 T1082 T1083 T1098 T1105 T1110 T1114 T1120 T1132 T1133 T1190 T1202 T1210 T1222 T1484.001 T1486 T1490 T1491 T1542 T1543.003 T1557 T1566 T1573 T1588 T1588.001 T1595 T1659
Remote Desktop Protocol
Lateral Movement
Distributed Component Object Model
Lateral Movement
Scheduled Task/Job
Execution
Process Injection
Defense Evasion
Keylogging
Collection
PowerShell
Execution
Web Protocols
Command And Control
DNS
Command And Control
Valid Accounts
Defense Evasion
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Account Manipulation
Persistence
Ingress Tool Transfer
Command And Control
Brute Force
Credential Access
Email Collection
Collection
Peripheral Device Discovery
Discovery
Data Encoding
Command And Control
External Remote Services
Persistence
Exploit Public-Facing Application
Initial Access
Indirect Command Execution
Defense Evasion
Exploitation of Remote Services
Lateral Movement
File and Directory Permissions Modification
Defense Evasion
Group Policy Modification
Defense Evasion
Data Encrypted for Impact
Impact
Inhibit System Recovery
Impact
Defacement
Impact
Pre-OS Boot
Defense Evasion
Windows Service
Persistence
Adversary-in-the-Middle
Credential Access
Phishing
Initial Access
Encrypted Channel
Command And Control
Obtain Capabilities
Resource Development
Malware
Resource Development
Active Scanning
Reconnaissance
Content Injection
Initial Access
Source Articles
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
DevMan, a ransomware-as-a-service (RaaS) operation also tracked as Funky Mantis, operates a centralized affiliate portal enabling payload generation, victim management, and payout coordination. The group evolved from affiliations with Qilin, DragonForce, and others, maintaining strong technical similarities to DragonForce ransomware. DevMan promotes attacks on critical infrastructure, including a specialized SCADA-targeting locker designed to cause physical system damage. The operation enforces strict governance over affiliates, uses an 80-20 revenue split, and has claimed 184 victims, primarily in the U.S. across technology, healthcare, and government sectors.
hacker-news ยท3d ago
โก Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
Multiple threat actors are leveraging compromised software supply chains, AI-driven attacks, and unpatched vulnerabilities to deploy malware, steal credentials, and conduct ransomware operations. Notable activities include the exploitation of Citrix Bleed 2 (CVE-2025-5777) for DragonForce ransomware deployment, a compromised npm package distributing a Rust-based stealer, and the emergence of HalluSquatting attacks targeting AI coding assistants. Additionally, new backdoors like GigaWiper and RedHook are being used for persistent access and data exfiltration across Windows and Android platforms.
hacker-news ยท2w ago