SophiaX
🔍
LIVE
· New victim: Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· New victim: 3,979 new IOCs ingested in last 24h Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· 3,979 new IOCs ingested in last 24h

DragonForce

🏛️ Nation-StateMotivation: financialLast active: 2026-08-06First seen: 2026-04-01
11
linked CVEs
Targeted industries
Agriculture and Food ProductionBusiness ServicesConstructionConsumer ServicesEducationEnergyFinancial ServicesHealthcareHospitality and TourismManufacturingNot FoundTechnologyTransportation/Logistics
Targeted regions
AEATAUBEBHBRCACHCNCYDEEGESFRGBGRHKILINITKRLBLKMXNENLNOPHPKRORUSASESGTHTRTWUAUSVNZA
DragonForce is a hacktivist group based in Malaysia that has been involved in cyberattacks targeting government institutions and commercial organizations in India. They have also targeted websites affiliated with Israel and have shown support for pro-Palestinian causes. The group has been observed using defacement attacks, distributed denial-of-service attacks, and data leaks as part of their campaigns. DragonForce Malaysia has demonstrated an ability to adapt and evolve their tactics over time.
Source: misp_galaxy · Collected: 2026-08-10
⚡ Vulnerabilities & Exploits11 CVEs
threat_actor_cve → cves / exploits.cve_ids
CVE-2023-4966
suspected

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

CVSS 9.4
KEVransomware
CVE-2025-0282
suspected

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

CVSS 9.0
KEVransomware
CVE-2025-5777
suspected

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

CVSS 7.5
KEVransomware
CVE-2024-57727
suspected

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.

CVSS 7.5
KEVransomware
CVE-2023-52271
suspected

CVE-2025-1055
suspected

CVE-2025-61155
suspected

CVE-2025-26399
suspected

SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.

KEVransomware
CVE-2026-4368
suspected

Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup

CVE-2024-57726
suspected

SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

KEVransomware
CVE-2024-57728
suspected

SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

KEVransomware
🔍 Detection Coverage5 Sigma
Derived from linked CVEs — not a direct actor match
highvia CVE-2023-4966
CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy
highvia CVE-2023-4966
CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Webserver
mediumvia CVE-2023-4966
CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy
mediumvia CVE-2023-4966
CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Webserver
highvia CVE-2025-26399
Suspicious Child Process of SolarWinds WebHelpDesk
windows
🧬 YaraComing soon
🛰️ Infrastructure & IOCs49
sha2568a4033425d36cd99fe23e6faef9764fbf555f362ebdb5b72379342fbbe4c55312026-07-16
md5ecb1d69999a730760b3c5654920f0ef62026-07-16
sha1b4ddb0adf94e28b53e392900c5ff2f538616441b2026-07-16
sha256048e18416177de2ead251abdf4d89837f6807c6aba4d5b1debe49adfdecbf05c2026-07-16
sha25665ab49119c845801f29a57e8aa177146b2ffbd289d4278109b146f933380f9512026-07-16
sha2566bbf10bcbef7ac5102b54c81137859891a3802dbacd888be90f990d50e18b0b42026-07-16
sha2566f9fbe29f8cc2788e2bc9d631e0eea2a8e9837076837b55838005a0e654f0a9e2026-07-16
sha256821da79d727351dd67ce5df7950e9a3de6647a3cf474bb3a093f67507fed92a62026-07-16
sha2568284c8676cc22c4b2e66826ac16986da7ddecba1f2776b16771be17bfdc45dc22026-07-16
sha25682b37a92589dfd4d67ca87eb9e52ac8e682e8e60d2211f59074cd5ccc693013b2026-07-16
sha2569335f61f8ad276d94455c5b6876fea48152c3cea759f2598c8108ee461fa57592026-07-16
sha256aea26980059ef2ad11e99556a4edfa1f8ec769fa9f06aa573b81bedf319954b52026-07-16
sha256cd078957167e1af4de39aecdb981cd14156fa81d5a9c6ac51e74ae5b6199a12a2026-07-16
sha256ce66b8221446c9b6d83f0ce6382f430e519601641e5daaaf1ca7a8a8806cb0b02026-07-16
sha256d0da2832ae1e13a98f7ce7e33a66c1b0d9797b81f69ece134e4462ea55ac923e2026-07-16
sha256d20a3c928761fe00ac522eeb474612b5804cd9108453ea8591106d5d4428428e2026-07-16
sha256e45b18c93d187aac5c4486f57483bc87580e15def82a312bfb377ff16eb96b222026-07-16
sha256f174c19902523dcf005fa044b6598403a5e5c0a5982398d1bc0dcc5ec1cd351b2026-07-16
urlhttp://192.36.27.51/TechSupV18Fix3.zip2026-07-16
domaincomunidadesparentais.com.br2026-07-16
domainglanz-gmbh.de2026-07-16
domainmysimerp.net2026-07-16
domainprofessionalhomebasedbusiness.com2026-07-16
domainprojetosmecanicos.com.br2026-07-16
domainsafefire.jo2026-07-16
domainsocialbizsolutions.com2026-07-16
domainturnkeyaiagents.com2026-07-16
domainopa.tlsd.shop2026-07-09
domainrelay.dltsolutions.top2026-07-09
domainrelay.eurofin.digital2026-07-09
domaintemp.sh2026-07-09
domainvtps.us2026-07-09
sha256c4fcae3847946173bf0b3cedf5d97a9e3d18090023842f942ba544fa7fda180d2026-07-09
sha256c84739655ce1af0a0269138263d47567418f69e0f75e249f8e23bc21802209e22026-07-09
sha256eb083365dc70d0294e8c4f55a2e78be0edb0f3497f2a06a70c9f474dafab48d82026-07-09
urlhttps://opa.tlsd.shop2026-07-09
sha2561aed62a63b4802e599bbd33162319129501d603cceeb5e1eb22fd4733b3018a32026-06-02
sha2569165d4f3036919a96b86d24b64d75d692802c7513f2b3054b20be40c212240a52026-06-02
md597b70e89b5313612a9e7a339ee82ab672026-06-02
md5a50637f5f7a3e462135c0ae7c7af0d912026-06-02
md5bb7c575e798ff5243b5014777253635d2026-06-02
sha256bfc2ef3b404294fe2fa05a8b71c7f786b58519175b7202a69fe30f45e607ff1c2026-06-02
md5c111476f7b394776b515249ecb6b20e62026-06-02
ip185.59.221.752026-06-02
ip185.73.125.82026-06-02
ip2.147.68.962026-06-02
ip69.4.234.202026-06-02
ip94.232.46.2022026-06-02
urlhttp://z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion/blog2026-06-02
📰 Threat Intel Coverage9
Digest reports mentioning this actor (incl. aliases)
CitrixBleed 2 (CVE-2025-5777) 7Steps to Dragonforce Ransomware | Huntressmatched as DragonForce2026-07-09
Connecting Scattered Spider: Defining A Cybercrime Collective Through Shared TTPsmatched as DragonForce2026-07-07
Killing me gently: Inside Gentlemen’s EDR killer frameworkmatched as DragonForce2026-06-18
Threats to the 2026 FIFA World Cupmatched as DragonForce2026-06-04
DragonForce Ransomware Group | Group-IB Blogmatched as DragonForce2026-06-02
Ransomware’s back office: What the ransom note won’t saymatched as DragonForce2026-04-20
Six Supply Chain Attack Groups to Watch Out for in 2026matched as DragonForce2026-03-27
EDR killers explained: Beyond the driversmatched as DragonForce2026-03-19
The LockBit’s Attempt to Stay Relevant, Its Imposters and New Opportunistic Ransomware Groupsmatched as Dragonforce2024-04-11