DragonForce Ransomware Group is Targeting Saudi Arabia
Feb. 28, 2025, 9:55 a.m.
Description
DragonForce ransomware has targeted organizations in Saudi Arabia, with a significant data leak from a Riyadh real estate and construction company. The group exfiltrated over 6 TB of data, setting a deadline just before Ramadan. DragonForce operates on a RaaS model, offering high commission rates for affiliates and supporting various platforms. They use advanced techniques, including a customized CAPTCHA filter and encrypted communications. The group's builder offers flexibility in payload configuration, and they leverage legitimate tools for file transfers. DragonForce employs a dual extortion strategy and has been observed using specific CVEs for network infiltration. The targeting of Saudi Arabia raises concerns about critical infrastructure security in the region.
Tags
Date
- Created: Feb. 27, 2025, 7:28 p.m.
- Published: Feb. 27, 2025, 7:28 p.m.
- Modified: Feb. 28, 2025, 9:55 a.m.
Indicators
- 1250ba6f25fd60077f698a2617c15f89d58c1867339bfd9ee8ab19ce9943304b
- a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91
- dffd6021bb2bd5b0af676290809ec3a53191dd81c7f70a4b28688a362182986f
- 07ab218d5c865cb4fe78353340ab923e24a1f2881ec7206520651c5246b1a492
- a4dfa099e1f52256ad4a3b2db961e158832b739126b80677f82b0722b0ea5e59
- feab413f86532812efc606c3b3224b7c7080ae4aa167836d7233c262985f888c
- 9479a5dc61284ccc3f063ebb38da9f63400d8b25d8bca8d04b1832f02fac24de
- 330730d65548d621d46ed9db939c434bc54cada516472ebef0a00422a5ed5819
- ab7d8832e35bba30df50a7cca7cefd9351be4c5e8961be2d0b27db6cd22fc036
- 62cd46988f179edf8013515c44cbb7563fc216d4e703a2a2a249fe8634617700
- 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
- http://dragonforxxbp3awc7mzs5dkswrua3znqyx5roefmi4smjrsdi22xwqd.onion
- http://z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion
- http://kfgjwkho24xiwckcf53x7qyruobbkhx4eqn2c6oe4hprbn23rcp6qcqd.onion
- z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion
- kfgjwkho24xiwckcf53x7qyruobbkhx4eqn2c6oe4hprbn23rcp6qcqd.onion
- dragonforxxbp3awc7mzs5dkswrua3znqyx5roefmi4smjrsdi22xwqd.onion
Attack Patterns
- DragonForce
- DragonForce
- T1486
- T1070
- T1082
- T1083
- T1204
- T1140
- T1560
- T1562
- T1190
- T1090
Additional Informations
- Real Estate
- Construction
- Saudi Arabia