DragonForce
| CVE-2023-4966 suspected | Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. | CVSS 9.4 KEVransomware |
| CVE-2025-0282 suspected | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution. | CVSS 9.0 KEVransomware |
| CVE-2025-5777 suspected | Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | CVSS 7.5 KEVransomware |
| CVE-2024-57727 suspected | SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords. | CVSS 7.5 KEVransomware |
| CVE-2023-52271 suspected | — | |
| CVE-2025-1055 suspected | — | |
| CVE-2025-61155 suspected | — | |
| CVE-2025-26399 suspected | SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine. | KEVransomware |
| CVE-2026-4368 suspected | Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup | |
| CVE-2024-57726 suspected | SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role. | KEVransomware |
| CVE-2024-57728 suspected | SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user. | KEVransomware |
| sha256 | 8a4033425d36cd99fe23e6faef9764fbf555f362ebdb5b72379342fbbe4c5531 | — | 2026-07-16 |
| md5 | ecb1d69999a730760b3c5654920f0ef6 | — | 2026-07-16 |
| sha1 | b4ddb0adf94e28b53e392900c5ff2f538616441b | — | 2026-07-16 |
| sha256 | 048e18416177de2ead251abdf4d89837f6807c6aba4d5b1debe49adfdecbf05c | — | 2026-07-16 |
| sha256 | 65ab49119c845801f29a57e8aa177146b2ffbd289d4278109b146f933380f951 | — | 2026-07-16 |
| sha256 | 6bbf10bcbef7ac5102b54c81137859891a3802dbacd888be90f990d50e18b0b4 | — | 2026-07-16 |
| sha256 | 6f9fbe29f8cc2788e2bc9d631e0eea2a8e9837076837b55838005a0e654f0a9e | — | 2026-07-16 |
| sha256 | 821da79d727351dd67ce5df7950e9a3de6647a3cf474bb3a093f67507fed92a6 | — | 2026-07-16 |
| sha256 | 8284c8676cc22c4b2e66826ac16986da7ddecba1f2776b16771be17bfdc45dc2 | — | 2026-07-16 |
| sha256 | 82b37a92589dfd4d67ca87eb9e52ac8e682e8e60d2211f59074cd5ccc693013b | — | 2026-07-16 |
| sha256 | 9335f61f8ad276d94455c5b6876fea48152c3cea759f2598c8108ee461fa5759 | — | 2026-07-16 |
| sha256 | aea26980059ef2ad11e99556a4edfa1f8ec769fa9f06aa573b81bedf319954b5 | — | 2026-07-16 |
| sha256 | cd078957167e1af4de39aecdb981cd14156fa81d5a9c6ac51e74ae5b6199a12a | — | 2026-07-16 |
| sha256 | ce66b8221446c9b6d83f0ce6382f430e519601641e5daaaf1ca7a8a8806cb0b0 | — | 2026-07-16 |
| sha256 | d0da2832ae1e13a98f7ce7e33a66c1b0d9797b81f69ece134e4462ea55ac923e | — | 2026-07-16 |
| sha256 | d20a3c928761fe00ac522eeb474612b5804cd9108453ea8591106d5d4428428e | — | 2026-07-16 |
| sha256 | e45b18c93d187aac5c4486f57483bc87580e15def82a312bfb377ff16eb96b22 | — | 2026-07-16 |
| sha256 | f174c19902523dcf005fa044b6598403a5e5c0a5982398d1bc0dcc5ec1cd351b | — | 2026-07-16 |
| url | http://192.36.27.51/TechSupV18Fix3.zip | — | 2026-07-16 |
| domain | comunidadesparentais.com.br | — | 2026-07-16 |
| domain | glanz-gmbh.de | — | 2026-07-16 |
| domain | mysimerp.net | — | 2026-07-16 |
| domain | professionalhomebasedbusiness.com | — | 2026-07-16 |
| domain | projetosmecanicos.com.br | — | 2026-07-16 |
| domain | safefire.jo | — | 2026-07-16 |
| domain | socialbizsolutions.com | — | 2026-07-16 |
| domain | turnkeyaiagents.com | — | 2026-07-16 |
| domain | opa.tlsd.shop | — | 2026-07-09 |
| domain | relay.dltsolutions.top | — | 2026-07-09 |
| domain | relay.eurofin.digital | — | 2026-07-09 |
| domain | temp.sh | — | 2026-07-09 |
| domain | vtps.us | — | 2026-07-09 |
| sha256 | c4fcae3847946173bf0b3cedf5d97a9e3d18090023842f942ba544fa7fda180d | — | 2026-07-09 |
| sha256 | c84739655ce1af0a0269138263d47567418f69e0f75e249f8e23bc21802209e2 | — | 2026-07-09 |
| sha256 | eb083365dc70d0294e8c4f55a2e78be0edb0f3497f2a06a70c9f474dafab48d8 | — | 2026-07-09 |
| url | https://opa.tlsd.shop | — | 2026-07-09 |
| sha256 | 1aed62a63b4802e599bbd33162319129501d603cceeb5e1eb22fd4733b3018a3 | — | 2026-06-02 |
| sha256 | 9165d4f3036919a96b86d24b64d75d692802c7513f2b3054b20be40c212240a5 | — | 2026-06-02 |
| md5 | 97b70e89b5313612a9e7a339ee82ab67 | — | 2026-06-02 |
| md5 | a50637f5f7a3e462135c0ae7c7af0d91 | — | 2026-06-02 |
| md5 | bb7c575e798ff5243b5014777253635d | — | 2026-06-02 |
| sha256 | bfc2ef3b404294fe2fa05a8b71c7f786b58519175b7202a69fe30f45e607ff1c | — | 2026-06-02 |
| md5 | c111476f7b394776b515249ecb6b20e6 | — | 2026-06-02 |
| ip | 185.59.221.75 | — | 2026-06-02 |
| ip | 185.73.125.8 | — | 2026-06-02 |
| ip | 2.147.68.96 | — | 2026-06-02 |
| ip | 69.4.234.20 | — | 2026-06-02 |
| ip | 94.232.46.202 | — | 2026-06-02 |
| url | http://z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion/blog | — | 2026-06-02 |
| CitrixBleed 2 (CVE-2025-5777) 7Steps to Dragonforce Ransomware | Huntress | matched as DragonForce | 2026-07-09 |
| Connecting Scattered Spider: Defining A Cybercrime Collective Through Shared TTPs | matched as DragonForce | 2026-07-07 |
| Killing me gently: Inside Gentlemen’s EDR killer framework | matched as DragonForce | 2026-06-18 |
| Threats to the 2026 FIFA World Cup | matched as DragonForce | 2026-06-04 |
| DragonForce Ransomware Group | Group-IB Blog | matched as DragonForce | 2026-06-02 |
| Ransomware’s back office: What the ransom note won’t say | matched as DragonForce | 2026-04-20 |
| Six Supply Chain Attack Groups to Watch Out for in 2026 | matched as DragonForce | 2026-03-27 |
| EDR killers explained: Beyond the drivers | matched as DragonForce | 2026-03-19 |
| The LockBit’s Attempt to Stay Relevant, Its Imposters and New Opportunistic Ransomware Groups | matched as Dragonforce | 2024-04-11 |