ZeroFox Intelligence Flash Report - DragonForce Announces New Service Updates
|by Alpha Team

ZeroFox Intelligence Flash Report - DragonForce Announces New Service Updates
Product Serial: F-2025-08-08a
TLP:CLEAR
In this Flash report, ZeroFox researchers report on a recent announcement by an account associated with the ransomware and digital extortion (R&DE) collective DragonForce, related to new service updates .
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On July 31, 2025, an account associated with DragonForce, a ransomware and digital extortion (R&DE) collective, posted on the Russian-speaking dark web forum Russian Anonymous Marketplace (RAMP), announcing various new features for existing services, including updates for its crypto locker.
- In the post on RAMP, the account associated with DragonForce states that the lockers—which refer to the payload that encrypts target files—are now transitioning to a stable version from the previous beta version.
- ZeroFox observed a significant uptick in DragonForce activity, beginning in early April 2025—leading to the collective’s most prominent month, in which the group conducted at least 25 separate attacks.
- This latest announcement by DragonForce likely indicates that the collective seeks to remain a prominent threat actor in the R&DE space and attract new affiliates.
Tags: tlp:clear, dark web, threat actor