Target Industry
Indiscriminate, opportunistic targeting. Critical infrastructure, government, healthcare, manufacturing, education, and private enterprises are all at risk.
Overview
Recent dark web chatter suggests that DragonForce is attempting to formalise a cartel with two of the most prominent ransomware groups: LockBit and Qilin. If successful, this coalition could reshape the ransomware ecosystem, consolidating power among major RaaS (Ransomware-as-a-Service) operators.
The timing is significant. Qilin is currently the most active ransomware group, responsible for around 15% of global ransomware compromises in the last 30 days, while LockBit has relaunched under LockBit 5.0 following disruption by law enforcement in 2024. DragonForce itself restructured as a cartel in March 2025 and has since targeted competitors such as Mamona and BlackLock RaaS, while absorbing RansomHub.
Competition between RaaS offerings has intensified in 2025, with groups offering lower ransom cuts to affiliates (Qilin advertises an 85/15 split, LockBit up to 90% for top performers) and value-added services including legal and negotiation support, DDoS capabilities, and even AI-powered chatbots. DragonForce’s push for cartelisation appears aimed at stabilising an increasingly volatile and competitive market.
Impact
If operationalised, the cartel could lead to:
- Larger, more coordinated ransomware campaigns
- Greater consistency in extortion tactics (data theft, leaks, DDoS, harassment)
- Reduced inter-group conflict and victim overlap
- Slower RaaS innovation due to diminished market competition
- Increased financial, reputational, and operational damage to victims
Threat Assessment
Whether this cartel becomes a lasting alliance remains questionable. Historically, ransomware groups have struggled to maintain long-term partnerships due to competing financial motives, language and cultural divides (notably between Russian- and English-speaking operators), and distrust around profit-sharing. However, should the collaboration progress, it as potential to reshape targeting strategies.
By reducing public conflicts and coordinating terms, these actors may seek to maximise revenues while limiting fragmentation in the market. Therefore there is a realistic possibility of a more structured division of victims or geographies, fewer “gang-on-gang” disputes, and potentially more consistent extortion tactics across multiple brands.
The coalition, driven by DragonForce, is likely an attempt at quelling fears in the criminal landscape after the groups publicised attacks against competing RaaS. Furthermore is the cooperation holds, we are likely to see a slowing of RaaS innovation due to the lack of market competition.
Containment, Mitigations & Remediations
- Invest in dark web credential monitoring solutions to identify any leaked credentials before they can be used in an attempted attack. In 2025, 23% of ransomware attacks were reportedly initiated by the exploitation of compromised credentials.
- Strengthen negotiation playbooks: organisations should anticipate a more standardised set of demands and tactics from affiliates aligned with these groups.
- Enhance monitoring of entry vectors commonly used by these actors (RDP, VPN appliances, Citrix, Fortinet, phishing campaigns).
- Review crisis communication plans to prepare for harassment or public smear tactics, particularly if DragonForce’s hacktivist flair is integrated into cartel operations.
- Maintain a strong, intelligence led patching policy that prioritises vulnerabilities that are under active exploitation or those that have a published proof of exploit.
Threat Groups
Qilin:
Currently Qilin is the most active ransomware group accounting for 15% of all ransomware compromises over the past 30 days. In recent months Qilin advertises a 85%-15% split with affiliates and additional services such as in-house legal, negotiation support, and DDoS features, highly likely designed to compete against other RaaS. \
The group is known to target education, local government, and industrial firms, with regular use of triple/quadruple extortion (data theft, leaks, DDoS, and direct victim harassment). Multilingual communications and broad targeting make Qilin flexible across both Western and Asian markets.
Initial access:
- Credential theft (phished or reused credentials)
- Phishing and business-email-compromise (BEC) flows
- Exploitation of known server/OT/enterprise CVEs on exposed services
- Compromised third-party/vendor access and supply-chain footholds
LockBit:
After operations were impacted by law enforcement in 2024, LockBit has recently relaunched operations under LockBit 5.0 after a 4 month hiatus. The group is known for offering affiliates flexible RaaS options, sophisticated negotiation support, and aggressive extortion methods. Additionally the group offers affiliates between70% and 90% of ransom based on performance.
Historically LockBit targeting prioritises healthcare, manufacturing, government, and critical infrastructure across Europe and North America. Russian-speaking core operators, though affiliates span multiple regions and languages.
Initial access:
- Compromised RDP / cracked weak Remote Desktop credentials
- Stolen VPN/remote-admin credentials
- Phishing (malicious attachments, credential harvesting)
- Purchased access from Initial Access Brokers (IABs)
- Exploitation of unpatched internet-facing appliances and services
- Exposed management consoles and poorly-segmented Windows services.
DragonForce:
In March 2025, DragonForce publicly restructured itself as a ransomware cartel.
The group provides backend services such as admin panels, leak sites, encryption tooling to affiliates while permitting them to run other ransomware brands (Ransom Bay white label service). Active recruitment and promotion on Russian-language forums (e.g., RAMP) while maintaining English-facing outreach for global affiliate onboarding.
Initial access:
- Affiliate-sourced access (access bought or shared within cartel)
- Phishing and social-engineering
- Exposed RDP/VPN/remote admin interfaces
- Exploitation of public-facing vulnerabilities on network appliances and web apps
- Compromised MSP/third-party credentials for lateral pivoting
Tactics, Techniques, and Procedures
- Initial Access: Phishing (T1566), compromised RDP/VPN credentials (T1078), exploitation of public-facing applications (T1190), supply-chain compromise (T1195).
- Execution: Command and scripting interpreter (T1059), malware deployment via web shells and remote admin tools.
- Persistence: Valid accounts (T1078), registry modification (T1112).
- Exfiltration & Impact: Data staged for exfiltration (T1074), data encrypted for impact (T1486), data exfiltration over C2 channels (T1041), denial of service via network floods (T1498).
Intelligence Terminology Yardstick













