Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ DragonForce

🇲🇾DragonForce

🇲🇾 DragonForce is a tracked threat actor in the Clankerusecase corpus. Attributed to MY. Primary motivation: Criminal. We map 14 detection use cases to this actor across 44 MITRE ATT&CK techniques, with 4 threat-intel articles citing them. Active in our corpus from 2026-03-19 to 2026-07-25.

crit 4
View full actor card → All threat actors
14Use cases
4Articles
44Techniques
0IOCs

Known aliases

DragonForceDragonForce Malaysia

Top techniques

All other tracked techniques

Detection use cases (14)

DragonForce pre-encryption recovery-inhibit + service-kill burst (LockBit/Conti-lineage encryptor) AI · profile SΣDD DragonForce affiliate hands-on-keyboard via SimpleHelp/RMM remote-access tooling (T1219 → recon/impact) AI · profile SΣDD DevMan/Funky Mantis locker execution by known SHA256/MD5 hash Bespoke DevMan ransomware encryption artifacts: .devman extension and deterministic ransom note Bespoke DevMan pre-encryption recovery inhibition and event-log clearing Bespoke Suspicious browser extension installation Internal Infostealer — non-browser process accessing browser cookie/login DBs Internal Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal Remote service execution — PsExec / SMB lateral movement Internal OAuth consent / suspicious app grant Internal Ransomware-style mass file rename / extension change Internal LSASS process access / dump (credential theft) Internal

Threat-intel articles (4)