ctipilot.ch

DragonForce

actor · actor:dragonforce contradictedsingle-source

Ransomware-as-a-service operator; pipeline coverage includes SimpleHelp RMM exploitation and the first in-the-wild Microsoft Teams TURN-relay C2 (Backdoor.Turn) intrusion.

Coverage timeline
12
first 2026-05-07 → last 2026-07-26
Peak priority
high
5 high · 7 notable
Sources cited
46
35 hosts
Sections touched
10
active-threats, deep-dive, updates
Co-occurring entities
4
see Related entities below
ATT&CK techniques
30
pinned v19.2 · see below
2026-06-1712 appearances2026-07-26

ATT&CK techniques

30 techniques observed across 9 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Resource Development TA0042

T1587.001Develop Capabilities: Malware×1

Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoors (including backdoored images), packers, C2 protocols, and the creation of infected removable media. Adversaries may develop malware to support their operations, creating a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors.

Evidence: 2026-07-19/weekly-w29-thegentlemen-storm2697-status · ATT&CK page ↗

Initial Access TA0001

T1190Exploit Public-Facing Application×6

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-19/weekly-w29-thegentlemen-storm2697-status · 2026-07-19/weekly-w29-ch-eu-public-sector-ci-incidents · 2026-07-12/weekly-w28-vuln-status-rollup · 2026-07-12/weekly-w28-threat-actor-developments · 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗

T1199Trusted Relationship×2

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-07-26/weekly-w30-ch-eu-public-sector-third-party-incidents · 2026-07-19/weekly-w29-ch-eu-public-sector-ci-incidents · ATT&CK page ↗

T1566.004Phishing: Spearphishing Voice×1

Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.

Evidence: 2026-07-12/weekly-w28-threat-actor-developments · ATT&CK page ↗

Execution TA0002

T1574Hijack Execution Flow×1

Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs. Hijacking execution flow can be for the purposes of persistence, since this hijacked execution may reoccur over time. Adversaries may also use these mechanisms to elevate privileges or evade defenses, such as application control or other restrictions on execution.

Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗

Persistence TA0003

T1098Account Manipulation×1

Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.

Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

T1112Modify Registry×1

Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.

Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

T1136Create Account×1

Adversaries may create an account to maintain access to victim systems. With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.

Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗

T1136.001Create Account: Local Account×2

Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.

Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-07-12/weekly-w28-vuln-status-rollup · ATT&CK page ↗

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×3

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-07-12/weekly-w28-vuln-status-rollup · 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗

T1098Account Manipulation×1

Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.

Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

T1611Escape to Host×1

Adversaries may break out of a container or virtualized environment to gain access to the underlying host. This can allow an adversary access to other containerized or virtualized resources from the host level or to the host itself. In principle, containerized / virtualized resources should provide a clear separation of application functionality and be isolated from the host environment.

Evidence: 2026-07-12/weekly-w28-vuln-status-rollup · ATT&CK page ↗

Stealth TA0005

T1070Indicator Removal×1

Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.

Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

T1574Hijack Execution Flow×1

Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs. Hijacking execution flow can be for the purposes of persistence, since this hijacked execution may reoccur over time. Adversaries may also use these mechanisms to elevate privileges or evade defenses, such as application control or other restrictions on execution.

Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗

T1684.001Social Engineering: Impersonation×1

Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, adversaries may communicate with victims (via Phishing for Information, Phishing, or Internal Spearphishing) while impersonating a known sender such as an executive, colleague, or third-party vendor. Established trust can then be leveraged to accomplish an adversary’s ultimate goals, possibly against multiple victims.

Evidence: 2026-07-12/weekly-w28-threat-actor-developments · ATT&CK page ↗

Defense Impairment TA0112

T1112Modify Registry×1

Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.

Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

T1685Disable or Modify Tools×1

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗

Credential Access TA0006

T1003OS Credential Dumping×1

Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures. Credentials can then be used to perform Lateral Movement and access restricted information.

Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

T1555Credentials from Password Stores×1

Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.

Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗

T1555.003Credentials from Password Stores: Credentials from Web Browsers×1

Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers.

Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗

Discovery TA0007

T1018Remote System Discovery×1

Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as Ping, <code>net view</code> using Net, or, on ESXi servers, `esxcli network diag ping`.

Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗

T1046Network Service Discovery×1

Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.

Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗

Lateral Movement TA0008

T1021Remote Services×1

Adversaries may use Valid Accounts to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.

Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗

T1550.001Use Alternate Authentication Material: Application Access Token×1

Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.

Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

T1570Lateral Tool Transfer×1

Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.

Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

Command and Control TA0011

T1090Proxy×1

Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.

Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗

T1219Remote Access Tools×1

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.

Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

Exfiltration TA0010

T1567Exfiltration Over Web Service×1

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-07-26/weekly-w30-ch-eu-public-sector-third-party-incidents · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×4

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-07-26/weekly-w30-ch-eu-public-sector-third-party-incidents · 2026-07-19/weekly-w29-thegentlemen-storm2697-status · 2026-07-19/weekly-w29-ch-eu-public-sector-ci-incidents · 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗

T1499Endpoint Denial of Service×1

Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users. Endpoint DoS can be performed by exhausting the system resources those services are hosted on or exploiting the system to cause a persistent crash condition. Example services include websites, email services, DNS, and web-based applications. Adversaries have been observed conducting DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion.

Evidence: 2026-07-12/weekly-w28-vuln-status-rollup · ATT&CK page ↗

T1657Financial Theft×2

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-07-26/ifage-geneva-dragonforce-data-published-student-records · 2026-07-14/dragonforce-leak-claim-ifage-geneva-adult-education · ATT&CK page ↗

Story timeline

  1. 2026-07-26Swiss and European public-sector bodies carried the week's home-region incident load — and nearly every one was reached through a third party, a shared platform or a fiduciary, then followed by a disclosure that had to be walked back
    weekly-sector-patternsSwiss public-sector breaches and Romania's land registry share a shape — third-party access, and a 'not affected' claim the leak later contradicted
  2. 2026-07-26IFAGE Geneva — DragonForce publishes the stolen data, exposing student exam results the institute had said were unaffected
    updatesThe IFAGE Geneva leak went from claim to publication, and it contradicts the victim's own scoping of the breach
  3. 2026-07-19The Gentlemen (Storm-2697) status: ReliaQuest's Q2 2026 numbers put it ahead of Qilin on the ransomware leaderboard, and a European public-transport victim (Metro Mondego) landed this week
    weekly-long-runningThe Gentlemen status — ReliaQuest ranks it Q2's most-active operator (300 vs Qilin's 289) on an AI-accelerated affiliate kit; it hit Metro Mondego (Portugal)
  4. 2026-07-19Swiss and European public-sector, utility and transport organisations carried the week's home-region incident load — a land registry offline for days, two Swiss utilities/foundations hit through third parties, an EU transit ransomware and a EUR 1.7M telco enforcement
    weekly-sector-patternsW29 home-region incidents — ANCPI Romania offline for days, IWB Basel and Geneva's IFAGE breached, Metro Mondego ransomware, Wind Tre fined EUR 1.7M
  5. 2026-07-14DragonForce lists Geneva's IFAGE adult-education foundation on its leak site, claiming 850 GB — an attribution and volume IFAGE has not confirmed
    active-threatsDragonForce claims 850 GB from Geneva's IFAGE, layering an unconfirmed extortion listing onto a narrower April breach the foundation already disclosed
  6. 2026-07-12Vulnerability status roll-up — 2026-W28: what moved into exploitation, what reached KEV, and what to patch out-of-band
    weekly-vuln-rollup2026-W28 vuln roll-up — exploited: ColdFusion, CitrixBleed 2, Gitea, Langflow, Joomla wave; notable: HTTP.sys mechanics, KVM escape, Siemens SICAM 8, MOVEit
  7. 2026-07-12Threat-actor developments this week: Group-IB reframes Scattered Spider as a decentralised collective, and China- and Iran-nexus edge/ORB tradecraft advances
    weekly-researchActor developments this week — Group-IB recasts Scattered Spider as a decentralised collective; China/Iran edge, ORB and C2 tradecraft advance
  8. 2026-07-12Confirmed in-the-wild exploitation of internet-facing enterprise software converged this week — ColdFusion, Citrix NetScaler and Gitea all moved from 'at risk' to 'under attack'
    weekly-top-storiesExposed enterprise software under active attack this week — ColdFusion (KEV), CitrixBleed 2 → DragonForce, Gitea escalated to actively-exploited
  9. 2026-07-12Looking ahead — 2026-W28
    weekly-looking-aheadLooking ahead — 2026-W28: items already in motion for the coming weeks
  10. 2026-07-10CitrixBleed 2 (CVE-2025-5777) weaponised into a repeatable IAB kill chain ending in DragonForce ransomware (STAC3725)
    deep-diveHuntress reconstructs a productised CitrixBleed 2-to-DragonForce runbook: token theft, a registry-symlink SYSTEM escalation, then ransomware
  11. 2026-06-29ESET "Killing me gently" — a de-facto mid-year RaaS-tooling report
    weekly-annual-reports
  12. 2026-06-17DragonForce abuses Microsoft Teams TURN relays for C2 and chains four vulnerable drivers (BYOVD)
    deep-dive

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

collaborates with

attributed activity

Where this entity is cited

  • deep-dive2
  • weekly-sector-patterns2
  • weekly-annual-reports1
  • weekly-looking-ahead1
  • weekly-top-stories1
  • weekly-research1
  • weekly-vuln-rollup1
  • active-threats1
  • weekly-long-running1
  • updates1

Source distribution

  • attack.mitre.org10 (22%)
  • bleepingcomputer.com2 (4%)
  • helpnetsecurity.com2 (4%)
  • 20min.ch1 (2%)
  • autismuslink.ch1 (2%)
  • blog.talosintelligence.com1 (2%)
  • campeaoprovincias.pt1 (2%)
  • cybersecuritydive.com1 (2%)
  • other27 (59%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (46)

Entries about DragonForce (12)

2026-07-26 · view entry permalink →

HIGHNATOB1

Swiss and European public-sector bodies carried the week's home-region incident load — and nearly every one was reached through a third party, a shared platform or a fiduciary, then followed by a disclosure that had to be walked back

The week's confirmed incidents with a direct Swiss or European home-region nexus landed almost entirely on public-sector and critical-infrastructure bodies, and two structural patterns are more useful to defenders than any single victim.

The first is the access path: the breach rarely started inside the named victim. Swiss rolling-stock manufacturer Stadler Rail disclosed that the Everest group compromised a data-exchange platform it shares with a supplier and demanded CHF 10 million, which the company did not pay — "Ein von der cyberkriminellen Everest Group gefordertes Lösegeld in Höhe von zehn Millionen Franken bezahlte die Firma laut Mitteilung nicht", while its own production ran normally (swissinfo.ch, 2026-07-21). A Vaud fiduciary breach claimed by BravoX published more than 100,000 client files — some 220 GB — exposing tax and administrative records of roughly fifteen Nord-Vaudois municipalities and the personal tax file of a sitting cantonal State Councillor (Le Temps, 2026-07-22). A Bern autism-support foundation, Stiftung Autismuslink, confirmed that "grössere Datenmengen" were exfiltrated and its server temporarily encrypted (Stiftung Autismuslink, 2026-07); the INC Ransom RaaS group claimed the attack via a matching leak-site listing (Ransomware.live, 2026-07-24), and the foundation's constituency-relevance is that it serves Swiss cantonal education-directorate and disability-insurance-linked clients. In each case the sensitive public-sector data sat with a supplier, a fiduciary or a small third-party service organisation, not on a government perimeter.

The second pattern is a disclosure that had to be walked back. Geneva's IFAGE adult-education foundation had earlier framed its incident as affecting employee data; the attackers — the DragonForce group (ICTjournal, 2026-07-17) — published the stolen set, which included identity-document photographs, addresses and multi-year student exam results, and 20 minutes reported the disclosure "concerne tant des employés de l'institut que des bénéficiaires (étudiants, entreprises, etc.)" (20 minutes, 2026-07-24). The starkest reversal is Romania's national land registry ANCPI, which stated on 2026-07-20 that its databases "have not been affected"; the national cybersecurity directorate DNSC's interim report describes attackers compromising the authentication servers, entering VMware vCenter, enumerating all 1,083 virtual machines, deleting roughly 100 and encrypting ESXi hosts, and exfiltrating about two million ePayment-platform user records — "nume; e-mailuri; identificatori; hash-uri ale parolelor" (PS News relaying DNSC, 2026-07-24), with the report also noting the affected servers ran no antivirus.

Ein von der cyberkriminellen Everest Group gefordertes Lösegeld in Höhe von zehn Millionen Franken bezahlte die Firma laut Mitteilung nicht

swissinfo.ch 2026-07-21

atacatorii au extras aproximativ două milioane de înregistrări privind utilizatori ai platformei de plăți, care conțineau: nume; e-mailuri; identificatori; hash-uri ale parolelor

PS News (relaying the DNSC report) 2026-07-24

Leur divulgation par les cybercriminels concerne tant des employés de l'institut que des bénéficiaires (étudiants, entreprises, etc.).

20 minutes

Builds on: 2026-07-22/everest-ransomware-stadler-rail-supplier-platform-breach · 2026-07-24/bravox-vaud-fiduciary-municipalities-breach · 2026-07-25/stiftung-autismuslink-bern-inc-ransom-breach · 2026-07-26/ifage-geneva-dragonforce-data-published-student-records · 2026-07-26/ancpi-romania-dnsc-report-2m-epayment-records-exfiltrated · 2026-07-21/ancpi-romania-cadastre-databases-not-affected-update

synthesis26 Jul 23:44Zmulti-sourceOpen finding ↗

2026-07-26 · view entry permalink →

NOTABLEupdateNATOC2

IFAGE Geneva — DragonForce publishes the stolen data, exposing student exam results the institute had said were unaffected

UPDATE · originally covered DragonForce lists Geneva's IFAGE adult-education foundation on its leak site, claiming 850 GB — an attribution and volume IFAGE has not confirmed (2026-07-14)

the DragonForce listing against IFAGE — the Fondation pour la formation des adultes à Genève — is no longer an unverified leak-site claim. The group carried out its threat and published the data, which Le Temps reported had been done as of Thursday 2026-07-23: "Des photos de pièces d'identité, des adresses e-mail et postales, ainsi que des numéros de téléphone ou encore des résultats d'examens ont été publiés." — identity-document photographs, e-mail and postal addresses, telephone numbers and examination results (20 minutes, 2026-07-24). The same report states that their disclosure by the cybercriminals "concerne tant des employés de l'institut que des bénéficiaires (étudiants, entreprises, etc.)" — it covers both the institute's employees and its beneficiaries, meaning students and companies. It also cites an expert consulted by Le Temps who put the exposure at thousands of documents spanning several years and running to 2026. ICTjournal had reported the extortion threat a week earlier (ICTjournal, 2026-07-17).

The operationally interesting part is the gap between the victim's scoping and the published set. IFAGE's earlier public account of its incident placed the impact on employee data rather than student or pedagogical records; the leak contains multi-year examination results for students. First coverage flagged that the group's claimed volume already exceeded the institute's own disclosure, and publication has now settled that discrepancy in the attackers' favour. Nothing in the reporting identifies the initial-access vector, so no access-path lesson is available from this incident.

Contradiction: the sources and the victim do not agree on whether a ransom was ever demanded, and this entry does not resolve it. 20 minutes frames the publication as the consequence of an unpaid demand — "Si la rançon demandée n'était pas payée, les pirates informatiques qui s'en sont pris en avril à l'Ifage (Fondation pour la formation des adultes à Genève) promettaient de mettre en ligne les données dérobées" — while also reporting the foundation's own position that "La fondation avait aussi affirmé qu'elle n'avait pas reçu de demande de rançon, mais que, le cas échéant, elle refuserait de payer": it had received no ransom demand, but would refuse to pay if one came (20 minutes, 2026-07-24). ICTjournal is more definite on the demand's existence, reporting a week earlier that a ransom was now being demanded and that the group threatened to publish at the expiry of the ultimatum posted on its leak site (ICTjournal, 2026-07-17). A leak-site ultimatum naming a ransom the victim says never reached it is a common pattern and not necessarily either party misspeaking — demands are frequently posted publicly rather than delivered.

Des photos de pièces d'identité, des adresses e-mail et postales, ainsi que des numéros de téléphone ou encore des résultats d'examens ont été publiés.

Leur divulgation par les cybercriminels concerne tant des employés de l'institut que des bénéficiaires (étudiants, entreprises, etc.).

20 minutes
incident26 Jul 13:58ZcontradictedOpen finding ↗

2026-07-19 · view entry permalink →

HIGHNATOB2

Swiss and European public-sector, utility and transport organisations carried the week's home-region incident load — a land registry offline for days, two Swiss utilities/foundations hit through third parties, an EU transit ransomware and a EUR 1.7M telco enforcement

The home-region incident load this week fell almost entirely on public administration, utilities and transport — the profiled constituency's core — and split into three recognisable shapes.

Direct public-sector disruption. Romania's National Agency for Cadastre and Real Estate Publicity (ANCPI) — the authority running the national land-registry and cadastre systems (e-Terra, RENNS) used by citizens, notaries and banks — had all IT systems offline from 14 July after a confirmed cyberattack; a data-leak operator using the alias ByteToBreach (tracked by KELA) claims to have stolen citizen data and the e-Terra/RENNS source code from a copied GitLab server, deployed ransomware and begun deleting backups, which ANCPI disputes (Help Net Security, 2026-07-16). Portugal's Metro Mondego confirmed a 6 July ransomware attack on internal systems — claimed by TheGentlemen — that its IT/OT separation kept off the Metrobus service, a clean example of segmentation limiting blast radius (Campeão das Províncias, 2026-07-17).

Swiss organisations hit through their suppliers. The Basel canton utility IWB (electricity, gas, water, telecom) disclosed that a compromised external service provider exfiltrated ~40,000 customer meter records (names, addresses, meter numbers) — IWB's own systems and supply were unaffected and the Basel-Stadt data-protection officer assessed misuse risk as low (Netzwoche, 2026-07-15). Geneva adult-education foundation IFAGE was listed by DragonForce claiming 850 GB, layered onto a narrower April breach it had already disclosed — single-sourced and unconfirmed, a watch item rather than an established breach.

Enforcement and cross-border tax-data exposure. Italy's Garante fined Wind Tre EUR 1,715,600 with an unusually complete technical account: retail-staff vishing led to valid MFA'd access, then a pivot from a protected primary API to an unprotected secondary API and ~2 million sequential customerId requests exfiltrating 365,048 customers (Garante, 2026-07-16). Ernst & Young separately disclosed a third-party ITSM-platform breach exposing client tax data.

Builds on: 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · 2026-07-16/iwb-basel-third-party-provider-breach-40k-customer-records · 2026-07-14/dragonforce-leak-claim-ifage-geneva-adult-education · 2026-07-18/metro-mondego-thegentlemen-ransomware-portugal-transit · 2026-07-17/garante-wind-tre-vishing-api-enumeration-fine · 2026-07-19/ernst-young-third-party-itsm-platform-breach-client-tax-data · 2026-07-17/abacus-erp-unauth-rce-path-traversal-ncsc-ch

synthesis19 Jul 23:50Zmulti-sourceOpen finding ↗

Earlier coverage (9)

2026-07-19NOTABLEexploitedupdateNATOB2The Gentlemen (Storm-2697) status: ReliaQuest's Q2 2026 numbers put it ahead of Qilin on the ransomware leaderboard, and a European public-transport victim (Metro Mondego) landed this weekUpdate to the prior weekly's The Gentlemen (Storm-2697) profile. ReliaQuest's Q2 2026 threat-spotlight (2026-07-16) reports The Gentlemen posted 300 victims in the quarter versus Qilin's 289, ending Qilin's leaderboard dominance, and attributes the pace to aggressive affiliate recruitment plus a well-packaged intrusion kit (pre-compromised victim lists, custom EDR killers, GPO-based deployment tooling) and a "likely AI-accelerated iteration layer" for tool refresh — with Infosecurity Magazine independently corroborating the 300-vs-289 figures. A GuidePoint GRIT review (pre-window) frames the same concentration as a "four-headed monster" (Qilin, The Gentlemen, Akira, DragonForce), with the five most prolific Q2 groups collectively claiming over 40% of recorded attacks. Operationally, the group's reach touched the constituency this week: Portugal's Metro Mondego confirmed a 6 July ransomware attack claimed by The Gentlemen, contained to internal systems. No new initial-access CVE or vector is disclosed — the delta is the quantitative leaderboard reversal, the AI-tooling-cadence explanation, and the fresh European public-transport victim.2026-07-14NOTABLENATOC3DragonForce lists Geneva's IFAGE adult-education foundation on its leak site, claiming 850 GB — an attribution and volume IFAGE has not confirmedDragonForce has listed IFAGE — the Fondation pour la formation des adultes à Genève, a Geneva adult-education foundation — on its extortion leak site, claiming 850 GB of exfiltrated data (Inside IT, 2026-07-14). IFAGE had already disclosed a narrower April 2026 employee-data exfiltration; the DragonForce attribution and the 850 GB figure are single-sourced and unconfirmed by IFAGE. Treat as a watch item, not a confirmed breach.2026-07-12NOTABLENATOB2Looking ahead — 2026-W28Items already in motion, not predictions: the Dutch NIS2 Cyberbeveiligingswet enters into force 15 August 2026 (five weeks out) and the EU Cyber Resilience Act's 11 September vulnerability/incident-reporting obligation is ~60 days away; FINMA's post-quantum expectation-setting may harden into a binding circular; the Joomla extension file-upload wave's newest members (RSFiles!/Phoca) are patched but not yet exploited, and prior wave members reached CISA KEV within days; Unit 42 references an Expel write-up of The Gentlemen's suspected EDR-disable zero-day that has not yet published; and the STAC3725 initial-access broker continues weaponising CitrixBleed 2 against un-session-terminated NetScaler.2026-07-12NOTABLENATOB2Threat-actor developments this week: Group-IB reframes Scattered Spider as a decentralised collective, and China- and Iran-nexus edge/ORB tradecraft advancesGroup-IB published an actor-definition piece reframing Scattered Spider not as a single hierarchical group but as a decentralised cybercrime collective of small (3-5 person) subclusters unified by shared TTPs — explicitly recasting 0ktapus, Octo Tempest, UNC3944 and Muddled Libra as overlapping subcluster labels, not distinct groups — which explains why arrests of individual members have not degraded the whole. In parallel, state-nexus edge and command-and-control tradecraft advanced: Talos' China-nexus UAT-7810 expanded its ORB network with the LONGLEASH suite, Proofpoint's UNK_MassTraction exploited Roundcube as an edge device, and Check Point exposed Iran MOIS-linked Cavern Manticore's modular .NET C2. The registry gains actor:scattered-spider.2026-07-12NOTABLEexploitedNATOB1Vulnerability status roll-up — 2026-W28: what moved into exploitation, what reached KEV, and what to patch out-of-bandConsolidated status view of the week's vulnerabilities that demand action beyond the routine patch cycle. Confirmed exploited / KEV this week: Adobe ColdFusion CVE-2026-48282, Citrix NetScaler CitrixBleed 2 CVE-2025-5777, Gitea CVE-2026-20896, Langflow CVE-2026-55255, and the Joomla extension file-upload wave (CVE-2026-48908/56290/56291/48939). Public-exploit or full-mechanics disclosures raising urgency without confirmed ITW use: GhostLock Linux kernel LPE CVE-2026-43499 (public reliable exploit), Windows HTTP.sys CVE-2026-47291 (ZDI published exploitation mechanics), Linux KVM 'Januscape' CVE-2026-53359 (guest-to-host escape), BeyondTrust RS/PRA CVE-2026-40138 cluster. OT/CI note: Siemens SICAM 8 grid RTU firmware-signing bypass (CVE-2026-54798-801). See the linked operational entries for per-CVE detail.2026-07-12HIGHexploitedNATOB1Confirmed in-the-wild exploitation of internet-facing enterprise software converged this week — ColdFusion, Citrix NetScaler and Gitea all moved from 'at risk' to 'under attack'Three separate internet-facing enterprise products crossed into confirmed exploitation in 2026-W28: Adobe ColdFusion CVE-2026-48282 (one of the 1 July CVSS 10.0 RCEs) was exploited within two hours of public detail and added to CISA KEV; Citrix NetScaler's CitrixBleed 2 (CVE-2025-5777) was reconstructed by Huntress into a repeatable initial-access-broker kill chain ending in DragonForce ransomware, where stolen session tokens survive patching; and NCSC-CH escalated the Gitea Docker reverse-proxy auth bypass (CVE-2026-20896) to actively exploited. The operational reality: any exposed unpatched instance of these should be treated as compromised, not merely vulnerable — and for CitrixBleed 2, patching alone is insufficient.2026-07-10HIGHexploitedNATOB2CitrixBleed 2 (CVE-2025-5777) weaponised into a repeatable IAB kill chain ending in DragonForce ransomware (STAC3725)Huntress reconstructed a single, mechanically identical intrusion chain across at least six unrelated organisations in H1 2026, run by an initial-access broker (tracked by Sophos as STAC3725): pre-auth session-token theft via CitrixBleed 2 (CVE-2025-5777) on internet-facing Citrix NetScaler Gateway/AAA appliances, a portable registry-symlink local-privilege-escalation tool that abuses the Group Policy engine and the AppMgmt service to reach SYSTEM, ScreenConnect/Zoho Assist persistence, and — in the most progressed case — DragonForce ransomware. Any organisation running an unpatched NetScaler Gateway must patch and terminate all live sessions, because stolen tokens survive patching.2026-06-29NOTABLEESET "Killing me gently" — a de-facto mid-year RaaS-tooling reportBackground. The Gentlemen emerged in late 2025 as a RaaS operation founded by "hastalamuerte" (a former Qilin affiliate per Group-IB, previously affiliated with Embargo, LockBit, Medusa and BlackLock per PRODAFT).2026-06-17HIGHDragonForce abuses Microsoft Teams TURN relays for C2 and chains four vulnerable drivers (BYOVD)DragonForce ransomware ran C2 through Microsoft Teams TURN relays — first in-the-wild abuse of Teams relay infrastructure to hide C2 in legitimate Microsoft traffic, plus a four-driver BYOVD chain; two-month dwell at a services firm (Deep Dive, § 5).