DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
Blog

DragonForce Ransom Cartel Profits From Rivals’ Demise

By TheFinanceBase Team8 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

The apparent disappearance of RansomHub in April 2025 helped accelerate consolidation in the ransomware economy. DragonForce claimed that former RansomHub operators moved to its platform, while threat researchers observed increased activity from DragonForce and rival Qilin during the second quarter.

The evidence does not prove a complete merger or establish DragonForce’s exact profits. It does show how a white-label ransomware-as-a-service model can absorb displaced affiliates, expand under multiple brands, and make a ransomware group’s visible collapse look more like a transfer of business than an end to criminal activity.

Ransomware’s market shifted after RansomHub disappeared

RansomHub appeared to vanish from the ransomware ecosystem around April 2025. That disappearance may have reflected a shutdown, rebranding, an operational pause, law-enforcement pressure, or the movement of affiliates and infrastructure to other groups. A leak site going offline cannot, by itself, establish which explanation is correct.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

DragonForce said that RansomHub operators had migrated to its platform and reportedly published an alleged screenshot of RansomHub backend infrastructure. Researchers also observed an increase in DragonForce victim postings between April and June 2025. Those clues support the idea of an apparent migration, but they do not independently verify that all RansomHub personnel, affiliates, or systems joined DragonForce.

#1 Best Overall
Sale
WD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN
  • Slim durable design to help take your important files with you
  • Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
  • Back up smarter with included device management software[2] with defense against ransomware
  • Help secure your important files with password protection and hardware encryption
  • 3-year limited warranty

Dark Reading reported the development on July 31, 2025, drawing on observations and analysis from Check Point Research. The central story was not simply that DragonForce launched more attacks. It was that the group appeared well positioned to capture operators displaced when a rival platform weakened or disappeared.

How DragonForce’s “cartel” model works

DragonForce’s use of the word “cartel” describes a cooperative, white-label ransomware-as-a-service model. The core operation provides infrastructure and support, while affiliates conduct intrusions and may present their campaigns under customized names and branding.

In a conventional ransomware brand, investigators may associate a victim claim, encryptor, negotiation channel, and leak site with one recognizable group. White-label operations complicate that picture. Several apparently unrelated campaigns can rely on the same backend services, tooling, hosting, negotiation support, or data-publication infrastructure.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The core operator can therefore expand without personally managing every intrusion. Affiliates gain access to capabilities that would be expensive and time-consuming to build themselves, including:

  • Ransomware tooling and administrative panels
  • Hosting and leak-site capacity
  • Victim negotiation channels
  • Operational guidance and support
  • Established branding and recruitment networks

Revenue sharing gives both sides an incentive to participate. Affiliates can move quickly, while the platform operator gains more campaigns, geographic reach, and potential ransom income. However, “cartel” should not be read as proof of a rigid hierarchy or a single centrally controlled criminal organization. A ransomware name may refer to developers, affiliates, a malware family, a leak-site identity, or a loose ecosystem of associated operators.

What evidence suggested DragonForce was gaining ground?

DragonForce reportedly claimed more than 250 victims on its leak site, including 58 during Q2 2025. Check Point Research’s comparison listed approximately 58 DragonForce victims for the quarter, alongside about 207 for Qilin and 143 for Akira.

These numbers are indicators of visible activity, not confirmed incident totals. Leak-site listings may represent claimed victims, duplicates, incomplete incidents, exaggerated claims, or organizations that did not pay. They do not establish that every listed organization was successfully compromised, that a ransom was paid, or that DragonForce generated a specific amount of profit.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
WD 4TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBPKJ0040BBK-WESN
  • Slim durable design to help take your important files with you
  • Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
  • Back up smarter with included device management software[2] with defense against ransomware
  • Help secure your important files with password protection and hardware encryption
  • 3-year limited warranty

The strongest interpretation is that DragonForce improved its market position. Its reported victim postings, public affiliate recruitment, claims about RansomHub, and alleged backend evidence all pointed in the same direction. “Profits” in the headline is therefore an inference about commercial growth in the criminal market, not a verified figure for revenue, payment volume, margins, or affiliate payouts.

Qilin was another beneficiary

DragonForce was not the only group positioned to benefit from RansomHub’s apparent decline. Check Point Research reported that Qilin’s activity nearly doubled in Q2 2025, rising from an average of roughly 35 victims per month to nearly 70.

Qilin was described as an established RaaS operation offering an encryptor, administrative infrastructure, negotiation services, and affiliate support. It also reportedly promoted stronger affiliate recruitment, distributed-denial-of-service capabilities, and negotiation consultations designed to increase pressure on victims.

This matters because it changes the interpretation of the market shift. The apparent collapse of one platform did not create a DragonForce monopoly. It created an opportunity for multiple established providers to recruit displaced operators. A reduction in visible ransomware brands can therefore coexist with substantial capacity behind the brands that remain.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why affiliates switch ransomware platforms

Ransomware affiliates are not permanently tied to one brand. When a provider disappears, suffers an infrastructure failure, loses credibility, or attracts excessive attention, affiliates need replacement tooling and operational support.

A mature platform can attract them faster than a new group can build an encryptor, establish a leak site, recruit negotiators, and develop a reputation in criminal forums. White-label access also lets an affiliate preserve a separate identity while benefiting from the provider’s infrastructure.

Benefits for affiliates

  • Faster access to working ransomware tools
  • Less need to build payment and negotiation systems
  • Ability to operate under a distinct name
  • Access to established publication and hosting infrastructure
  • Reduced administrative and technical overhead

Benefits for the platform operator

  • More campaigns without directly managing every intrusion
  • Broader sector and geographic coverage
  • Additional revenue-sharing opportunities
  • Greater resilience if one affiliate is exposed or arrested

The model also creates weaknesses. Affiliates depend on the provider’s availability and may lose access to negotiations or stolen data after a shutdown. Shared tooling can expose links between supposedly separate campaigns. Poor affiliate behavior can bring law-enforcement attention to the wider platform, and disputes can arise over branding, revenue, and victim handling.

Rank #3
Sale
WD 6TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBR9S0060BBK-WESN
  • World’s First 6TB 2.5” Portable Hard Drive
  • Slim durable design to help take your important files with you
  • Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
  • Back up smarter with included device management software[2] with defense against ransomware
  • Help secure your important files with password protection and hardware encryption

From encryption to data-theft extortion

The Q2 2025 reporting also highlighted a broader shift toward data theft and extortion without necessarily encrypting every victim’s systems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Double extortion combines data theft with encryption: attackers threaten to publish stolen information while disrupting access to the victim’s systems. Data-theft-only operations rely primarily on the threat of disclosure. Either approach can be damaging. A victim may face regulatory exposure, litigation, operational disruption, reputational harm, and pressure from customers or employees even if no files are encrypted.

Researchers suggested that encryption attacks, particularly against healthcare organizations, can generate greater law-enforcement attention. That may encourage some criminals to target less critical organizations or emphasize theft and extortion instead. This is an observed explanation, not a universal rule; attackers continue to use different combinations of encryption, theft, harassment, and public disclosure.

Public leak sites are part of that pressure system. Negotiation services, deadline announcements, alleged proof of theft, and threats to release data can be used to increase urgency. The absence of encryption should not be treated as evidence that an incident is minor.

DragonForce’s claimed healthcare restrictions are not a safety guarantee

DragonForce reportedly announced stricter affiliate screening and said affiliates should avoid healthcare targets. The group framed its objective as financial gain rather than physical harm.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Those are self-imposed policies by a criminal organization, not reliable protections. They can be ignored, changed, or selectively enforced. Healthcare organizations remain attractive targets because they hold sensitive data, depend heavily on availability, and may face intense pressure to restore services quickly.

Security teams should therefore treat the reported policy as a branding and risk-management tactic rather than a defensive control.

Rank #4
SonicWall Advanced Protection Service Suite for NSA3700-3 Year License (02-SSC-6910) - Capture ATP, App Control, Threat Prevention & 24x7 Support
  • SonicWall Advanced Protection Service Suite for NSA3700 - 3 Year License (02-SSC-6910)
  • Capture ATP with RTDMI for Enterprise: Defend against zero-day exploits and ransomware using multi-engine cloud sandboxing and advanced memory inspection.
  • Full Threat Protection Stack: Includes Gateway AV, Intrusion Prevention, Anti-Spyware, Application Control, and Content Filtering for layered defense.
  • 24x7 Global Support & Firmware Updates: Keep your firewall protected and operational with continuous technical assistance and critical firmware upgrades.
  • Application Intelligence & Network Control: Identify and control network activity with deep traffic analytics and reporting features.

Marketing helped DragonForce compete

Ransomware platforms compete for affiliates, not just victims. Recruitment, reputation, support, and perceived reliability can matter as much as malware capability.

DragonForce promoted its cartel model on criminal forums, and the RAMP forum reportedly incorporated the DragonForce name into its logo at one point. Public recruitment could help attract operators displaced by RansomHub’s apparent disappearance. A visible brand can signal that a platform has functioning tooling, infrastructure, and victim-support processes.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That visibility has a trade-off: marketing may attract affiliates, but it also creates more information for researchers and law enforcement. The same public presence that builds trust in criminal markets can expose relationships, infrastructure, and operating patterns.

AI is part of the wider ransomware ecosystem

AI was a secondary development in the reporting, not an explanation for DragonForce’s rise. Check Point Research identified examples of ransomware actors using large-language-model tools or AI-related capabilities, including AI-assisted malware development, an AI-generated ransomware variant, and reported AI-powered negotiation support associated with Global Group, also known as El Dorado and BlackLock.

Such capabilities may help automate victim communications, refine psychological pressure, or speed parts of malware development. They do not prove that AI drove DragonForce’s expansion. The more immediate explanation for DragonForce’s reported growth was its platform model, recruitment strategy, branding, and ability to benefit from movement among affiliates.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What defenders should take away

Track behaviors, not only ransomware names

Brand names can change quickly. Monitoring should also focus on data exfiltration, unusual administrative activity, credential abuse, remote-access tools, privilege escalation, lateral movement, and connections to known criminal infrastructure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prepare for rebranding and platform migration

An apparent shutdown does not mean the threat has disappeared. Threat intelligence teams should look for reused tooling, infrastructure, negotiation patterns, file extensions, ransom-note language, and affiliate behaviors across changing brands.

Best Value
Sale
WD 5TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBPKJ0050BBK-WESN
  • Slim durable design to help take your important files with you
  • Back up smarter with included device management software[2] with defense against ransomware
  • Help secure your important files with password protection and hardware encryption
  • 3-year limited warranty

Investigate data theft even without encryption

Incident response plans should include rapid assessment of exfiltration, identity and access controls, cloud storage, privileged accounts, backup exposure, and potential disclosure obligations. A system that remains operational may still be involved in a serious extortion event.

Review third-party and MSP access

Because affiliates may use compromised credentials and trusted remote-management paths, organizations should review vendor accounts, enforce least privilege, require multifactor authentication, monitor remote access, and ensure that service-provider incident procedures are tested.

Treat leak-site claims as leads

A listing can provide useful intelligence about a possible incident, but it requires validation. Security teams should confirm whether data belongs to the organization, determine when and how it was accessed, preserve evidence, and coordinate legal, regulatory, communications, and law-enforcement decisions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The larger lesson

The important development was not simply that DragonForce became more active after RansomHub disappeared. It was that the ransomware-as-a-service market appeared capable of absorbing the collapse of a major brand and redirecting operators toward better-positioned platforms.

Disrupting a leak site or ransomware name can impose real costs, but it may not eliminate the underlying criminal capability. Affiliates, access brokers, payment channels, infrastructure providers, and recruitment networks can reassemble under another identity. For defenders, resilience depends on tracking those underlying behaviors and relationships rather than assuming that the disappearance of one brand marks the end of the threat.

Frequently Asked Questions

Did RansomHub definitely merge with DragonForce?

No. DragonForce claimed that former RansomHub operators migrated to its platform, and researchers observed related signs, but the available evidence does not prove a complete merger or the transfer of every RansomHub affiliate and system.

Did DragonForce’s victim count prove its profits?

No. Reported leak-site listings indicate visible activity, not confirmed compromises, successful ransom payments, total revenue, or profit margins.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Are healthcare organizations protected by DragonForce’s reported policy?

No. The reported restriction was self-imposed by a criminal group and could be ignored, changed, or selectively enforced.

Quick Recap

SaleBestseller No. 1
WD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN
WD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN
Slim durable design to help take your important files with you; Help secure your important files with password protection and hardware encryption
$129.00
Bestseller No. 2
WD 4TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBPKJ0040BBK-WESN
WD 4TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBPKJ0040BBK-WESN
Slim durable design to help take your important files with you; Help secure your important files with password protection and hardware encryption
$180.10
SaleBestseller No. 3
WD 6TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBR9S0060BBK-WESN
WD 6TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBR9S0060BBK-WESN
World’s First 6TB 2.5” Portable Hard Drive; Slim durable design to help take your important files with you
$259.00
Bestseller No. 4
SonicWall Advanced Protection Service Suite for NSA3700-3 Year License (02-SSC-6910) - Capture ATP, App Control, Threat Prevention & 24x7 Support
SonicWall Advanced Protection Service Suite for NSA3700-3 Year License (02-SSC-6910) - Capture ATP, App Control, Threat Prevention & 24x7 Support
SonicWall Advanced Protection Service Suite for NSA3700 - 3 Year License (02-SSC-6910)
$11,163.19
SaleBestseller No. 5
WD 5TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBPKJ0050BBK-WESN
WD 5TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBPKJ0050BBK-WESN
Slim durable design to help take your important files with you; Help secure your important files with password protection and hardware encryption
$213.00

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.