Advisories

ZeroFox Intelligence Flash Report - Rumored New Coalition of Ransomware Groups Yet to Materialize

|by Alpha Team

banner image

ZeroFox Intelligence Flash Report - Rumored New Coalition of Ransomware Groups Yet to Materialize

Product Serial: F-2025-10-10a

TLP:CLEAR

In this Flash report, ZeroFox researchers report on the recent claims made by DragonForce that they have allegedly formed a coalition with other prominent threat collectives Qilin and LockBit.

Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • On September 15, 2025, an account associated with the ransomware and digital extortion (R&DE) collective DragonForce posted on the dark web forum Russian Anonymous Marketplace (RAMP), announcing a coalition with Qilin and LockBit, two other prominent ransomware-as-a-service (RaaS) collectives.
  • In the post, DragonForce explained that the coalition is about uniting efforts as they collaboratively develop their direction—likely meaning that the collectives will assist each other in enhancing their products and services to better serve their affiliates and maximize profits, while also evading law enforcement (LE).
  • Notably, ZeroFox has not observed either Qilin or LockBit publicly confirming or denying the alleged coalition. However, both Qilin and LockBit are known to post only rarely on RAMP.
  • It is unlikely that DragonForce’s announcement of a coalition with LockBit and Qilin represents a formalized amalgamation of the three collectives.

Tags: tlp:clear dark web threat actor