ZeroFox Intelligence Flash Report - Rumored New Coalition of Ransomware Groups Yet to Materialize
|by Alpha Team

ZeroFox Intelligence Flash Report - Rumored New Coalition of Ransomware Groups Yet to Materialize
Product Serial: F-2025-10-10a
TLP:CLEAR
In this Flash report, ZeroFox researchers report on the recent claims made by DragonForce that they have allegedly formed a coalition with other prominent threat collectives Qilin and LockBit.
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On September 15, 2025, an account associated with the ransomware and digital extortion (R&DE) collective DragonForce posted on the dark web forum Russian Anonymous Marketplace (RAMP), announcing a coalition with Qilin and LockBit, two other prominent ransomware-as-a-service (RaaS) collectives.
- In the post, DragonForce explained that the coalition is about uniting efforts as they collaboratively develop their direction—likely meaning that the collectives will assist each other in enhancing their products and services to better serve their affiliates and maximize profits, while also evading law enforcement (LE).
- Notably, ZeroFox has not observed either Qilin or LockBit publicly confirming or denying the alleged coalition. However, both Qilin and LockBit are known to post only rarely on RAMP.
- It is unlikely that DragonForce’s announcement of a coalition with LockBit and Qilin represents a formalized amalgamation of the three collectives.
Tags: tlp:clear, dark web, threat actor