2026-09-29HIGHMicrosoft: the same toolkit rides into victims regardless of which ransomware brand signs the note
DragonForce
actor · actor:dragonforce single-source
Ransomware-as-a-service operator; pipeline coverage includes SimpleHelp RMM exploitation and the first in-the-wild Microsoft Teams TURN-relay C2 (Backdoor.Turn) intrusion.
Coverage
5
first 2026-05-07 → last 2026-09-29
Latest activity
2026-09-29
Microsoft: the same toolkit rides into victims regardless of which ransomware brand signs the note
Peak priority
high
3 high · 2 notable
Targets
public-sector
sectors: public-sector, healthcare, education · regions: us, europe, switzerland
Sources cited
23
13 hosts
2026-06-175 appearances2026-09-29
Action items (5)
Do-now tasks recorded on the entries about DragonForce, newest first. Check the date before acting on an older one.
- Patch every internet-facing NetScaler ADC/Gateway to the fixed build in Citrix's NetScaler security bulletin for CVE-2025-5777 now, and after patching terminate ALL active ICA/PCoIP and AAA sessions; tokens harvested via CVE-2025-5777 remain valid across the patch.2026-07-10CVE-2025-5777
- Hunt NetScaler ns.log for a burst of AAA LOGIN_FAILED events carrying binary/unprintable User values from a single source IP, and for any authenticated session driven from an IP that has no preceding successful authentication.2026-07-10CVE-2025-5777
- Forward NetScaler logs off-box to a SIEM before hunting, on-device ns.log rotates fast enough to lose the evidence.2026-07-10CVE-2025-5777
- Alert on gpupdate followed closely by an AppMgmt (Application Management) service start and a new SYSTEM-context process, and on net user / net localgroup Administrators account creation outside change management.2026-07-10CVE-2025-5777
- Inventory endpoints for unexpected ScreenConnect, Zoho Assist, Netbird or Atera installs not tied to a sanctioned RMM deployment.2026-07-10CVE-2025-5777
Defender insights
What each entry about DragonForce tells a defender to do, newest first.
Triage
Triage
Latest update
Triage
Detection
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
collaborates with
- Ransom BustersGuidePoint states it observed the Ransom Busters outreach while responding to incidents involving DragonForce, and assesses the persona is an affiliate employed across the programmes it targets
- Storm-2570Microsoft: Storm-2570 operates as an affiliate deploying DragonForce ransomware as one of its RaaS-brand payloads.
attributed activity
Story timeline
- 2026-09-29Storm-2570: a ransomware affiliate reuses a consistent commodity RMM/tunnelling/credential-theft toolkit across four separate RaaS brands, with government agencies among its confirmed victims
- 2026-08-20"Ransom Busters" emails ransomware victims before their incident is public, offering to delete the stolen data for a fee, and the tooling says it is the same affiliate who took it
- 2026-07-14DragonForce lists Geneva's IFAGE adult-education foundation on its leak site, claiming 850 GB; an attribution and volume IFAGE has not confirmed
- 2026-07-10CitrixBleed 2 (CVE-2025-5777) weaponised into a repeatable IAB kill chain ending in DragonForce ransomware (STAC3725)
- 2026-06-17DragonForce abuses Microsoft Teams TURN relays for C2 and chains four vulnerable drivers (BYOVD)
Hunting pivots
CVEs (exploited first)
Affected products
ATT&CK techniques (29 across 12 tactics)
29 techniques observed across 5 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- ExecutionCommand and Scripting Interpreter: PowerShell · System Services: Service Execution · Hijack Execution Flow · Hijack Execution Flow: DLL
- PersistenceAccount Manipulation · Modify Registry · Create Account · Create Account: Local Account
- Privilege EscalationExploitation for Privilege Escalation · Account Manipulation
- StealthIndicator Removal · Hijack Execution Flow · Hijack Execution Flow: DLL
- Defense ImpairmentModify Registry · Disable or Modify Tools
- Credential AccessOS Credential Dumping · OS Credential Dumping: LSASS Memory · OS Credential Dumping: NTDS · Credentials from Password Stores · Credentials from Password Stores: Credentials from Web Browsers
- DiscoveryRemote System Discovery · Network Service Discovery
- Lateral MovementRemote Services · Remote Services: Remote Desktop Protocol · Use Alternate Authentication Material: Application Access Token · Lateral Tool Transfer
- Command and ControlProxy · Remote Access Tools · Protocol Tunneling
- ExfiltrationExfiltration Over Web Service: Exfiltration to Cloud Storage
- ImpactData Encrypted for Impact · Financial Theft
Initial Access TA0001
T1190Exploit Public-Facing Application×2
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
Execution TA0002
T1059.001Command and Scripting Interpreter: PowerShell×1
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).
Evidence: 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · ATT&CK page ↗
T1569.002System Services: Service Execution×1
Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (<code>services.exe</code>) is an interface to manage and manipulate services. The service control manager is accessible to users via GUI components as well as system utilities such as <code>sc.exe</code> and Net.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
T1574Hijack Execution Flow×1
Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs. Hijacking execution flow can be for the purposes of persistence, since this hijacked execution may reoccur over time. Adversaries may also use these mechanisms to elevate privileges or evade defenses, such as application control or other restrictions on execution.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
Persistence TA0003
T1098Account Manipulation×1
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
T1112Modify Registry×1
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
T1136Create Account×1
Adversaries may create an account to maintain access to victim systems. With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
T1136.001Create Account: Local Account×3
Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.
Evidence: 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation×2
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
T1098Account Manipulation×1
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
Stealth TA0005
T1070Indicator Removal×1
Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
T1574Hijack Execution Flow×1
Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs. Hijacking execution flow can be for the purposes of persistence, since this hijacked execution may reoccur over time. Adversaries may also use these mechanisms to elevate privileges or evade defenses, such as application control or other restrictions on execution.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
Defense Impairment TA0112
T1112Modify Registry×1
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
T1685Disable or Modify Tools×2
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
Credential Access TA0006
T1003OS Credential Dumping×1
Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures. Credentials can then be used to perform Lateral Movement and access restricted information.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
T1003.001OS Credential Dumping: LSASS Memory×1
Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
T1003.003OS Credential Dumping: NTDS×1
Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in <code>%SystemRoot%\NTDS\Ntds.dit</code> of a domain controller.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
T1555Credentials from Password Stores×2
Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
T1555.003Credentials from Password Stores: Credentials from Web Browsers×1
Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
Discovery TA0007
T1018Remote System Discovery×1
Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as Ping, <code>net view</code> using Net, or, on ESXi servers, `esxcli network diag ping`.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
T1046Network Service Discovery×3
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
Lateral Movement TA0008
T1021Remote Services×1
Adversaries may use Valid Accounts to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
T1021.001Remote Services: Remote Desktop Protocol×1
Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
T1550.001Use Alternate Authentication Material: Application Access Token×1
Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
T1570Lateral Tool Transfer×2
Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
Command and Control TA0011
T1090Proxy×1
Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
T1219Remote Access Tools×3
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
T1572Protocol Tunneling×1
Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · ATT&CK page ↗
Exfiltration TA0010
T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×2
Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.
Evidence: 2026-09-29/microsoft-storm-2570-cross-raas-toolkit · 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · ATT&CK page ↗
Impact TA0040
T1486Data Encrypted for Impact×1
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
T1657Financial Theft×2
Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.
Evidence: 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · 2026-07-14/dragonforce-leak-claim-ifage-geneva-adult-education · ATT&CK page ↗
Entries about DragonForce (5)
Earlier coverage (2)
CitrixBleed 2 (CVE-2025-5777) weaponised into a repeatable IAB kill chain ending in DragonForce ransomware (STAC3725)Huntress reconstructed a single, mechanically identical intrusion chain across at least six unrelated organisations in H1 2026, run by an initial-access broker (tracked by Sophos as STAC3725): pre-auth session-token theft via CitrixBleed 2 (CVE-2025-5777) on internet-facing Citrix NetScaler Gateway/AAA appliances, a portable registry-symlink local-privilege-escalation tool that abuses the Group Policy engine and the AppMgmt service to reach SYSTEM, ScreenConnect/Zoho Assist persistence, and (in the most progressed case) DragonForce ransomware. Any organisation running an unpatched NetScaler Gateway must patch and terminate all live sessions, because stolen tokens survive patching.DragonForce abuses Microsoft Teams TURN relays for C2 and chains four vulnerable drivers (BYOVD)DragonForce ransomware ran C2 through Microsoft Teams TURN relays, first in-the-wild abuse of Teams relay infrastructure to hide C2 in legitimate Microsoft traffic, plus a four-driver BYOVD chain; two-month dwell at a services firm (Deep Dive, § 5).
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Anubis (ransomware-as-a-service)×2
- BERT (ransomware-as-a-service)×1
- Citrix NetScaler×1
- CitrixBleed 2 (NetScaler ADC/Gateway pre-auth memory over-read), weaponised in the STAC3725 IAB-to-DragonForce kill chain (Huntress)×1
- DragonForce Backdoor.Turn intrusion×1
- IFAGE Geneva, DragonForce leak-site claim (850 GB)×1
- Qilin×1
- Ransom Busters×1
Where this entity is cited
Source distribution
- attack.mitre.org10 (43%)
- bleepingcomputer.com2 (9%)
- 20min.ch1 (4%)
- guidepointsecurity.com1 (4%)
- helpnetsecurity.com1 (4%)
- huntress.com1 (4%)
- ictjournal.ch1 (4%)
- inside-it.ch1 (4%)
- other5 (22%)
All cited sources (23)
- 20min.ch20 minutes (Switzerland)https://www.20min.ch/fr/story/geneve-les-hackers-de-l-institut-ifage-ont-mis-leurs-menaces-a-execution-103608147
- attack.mitre.org`T1018`https://attack.mitre.org/techniques/T1018/
- attack.mitre.org`T1021`https://attack.mitre.org/techniques/T1021/
- attack.mitre.org`T1046`https://attack.mitre.org/techniques/T1046/
- attack.mitre.org`T1068` Exploitation for Privilege Escalationhttps://attack.mitre.org/techniques/T1068/
- attack.mitre.org`T1090` Proxyhttps://attack.mitre.org/techniques/T1090/
- attack.mitre.org`T1136.001`https://attack.mitre.org/techniques/T1136/001/
- attack.mitre.org`T1190` Exploit Public-Facing Applicationhttps://attack.mitre.org/techniques/T1190/
- attack.mitre.org`T1555.003`https://attack.mitre.org/techniques/T1555/003/
- attack.mitre.org`T1562.001` Impair Defenseshttps://attack.mitre.org/techniques/T1562/001/
- attack.mitre.org`T1574.002`https://attack.mitre.org/techniques/T1574/002/
- bleepingcomputer.comBleepingComputer, 2026-06-16https://www.bleepingcomputer.com/news/security/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-recovery-firm/
- guidepointsecurity.comGuidePoint Security (GRIT)https://www.guidepointsecurity.com/blog/beware-ransom-busters/
- helpnetsecurity.comHelp Net Security, 2026-06-16https://www.helpnetsecurity.com/2026/06/16/dragonforce-microsoft-teams-malware-backdoor-turn/
- huntress.comHuntresshttps://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware
- ictjournal.chICTjournalhttps://www.ictjournal.ch/news/2026-07-17/cyberattaque-contre-lifage-les-pirates-de-dragonforce-menacent-de-publier-la-masse
- inside-it.chInside IT Switzerlandhttps://www.inside-it.ch/ransomware-bande-bekennt-sich-zu-angriff-auf-genfer-erwachsenenbildung-20260714
- itsecurityguru.orgIT Security Guruhttps://www.itsecurityguru.org/2026/07/09/citrixbleed-2-exploited-in-repeatable-attack-chain-culminating-in-dragonforce-ransomware-researchers-find/
- latele.chLa Téléhttps://latele.ch/articles/la-fondation-ifage-a-geneve-victime-d-une-cyberattaque
- microsoft.comMicrosoft Security Blog / Microsoft Threat Intelligencehttps://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/
- security.comSymantec / Broadcom, 2026-06-16https://www.security.com/threat-intelligence/dragonforce-msteams-backdoor
- sophos.comSophos X-Opshttps://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery