Cyber Threat Actor: DragonForce
| Actor Type | Location | Known Incidents |
Activist
|
Malaysia
|
8 incidents |
|---|
Profile
DragonForce, also known as DragonForce Malaysia, is a hacker group that operates from Malaysia. Public sources describe the group as anti‑Israeli and pro‑Palestinian in its stated motivations. No explicit link to a state sponsor or a larger criminal consortium has been made public. The group has been observed conducting both financially motivated ransomware operations and ideologically driven disruption campaigns. Its activities are tracked through threat‑intelligence feeds, news reports, and claims posted on Telegram.
DragonForce has targeted Israeli banking websites, launching distributed denial‑of‑service attacks that peaked at about 200 Mbps to disrupt online services. In the same timeframe the group leaked a file purporting to contain names and addresses of Israeli students, which it presented as part of its pro‑Palestinian messaging. The group also claimed responsibility for a breach of the Israeli student recruitment platform AcadeME, exposing personal details of roughly 280 000 users. Beyond the Middle East, DragonForce has attacked a civil engineering firm (Sayre Associates), an insurance broker (Vercoe Insurance Brokers), and several retail companies including Harrods, Co‑op and Marks & Spencer. In the municipal sector, the group leaked citizen data from the City of Baden after exploiting an older vulnerability to obtain a backup copy. These incidents show a mix of financial goals—such as ransomware encryption and data extortion—and ideological aims like publishing personal data to advance a political narrative.
The group's observed tactics include deploying ransomware that encrypts files and exfiltrates data, as seen in the Sayre Associates and Vercoe incidents. It also relies on volumetric DDoS floods, with traffic volumes reported around 200 Mbps against banking and recruitment targets. Exploitation of unpatched or legacy systems has been cited, notably the use of an older security flaw to reach a backup database in the Baden case. Claims of responsibility are routinely posted on Telegram channels, sometimes accompanied by screenshots or leaked files as proof. Representative campaigns are the 2021 DDoS and student‑data leak against Israeli banks and AcadeME, the 2023 ransomware attack on Sayre Associates, the 2025 data exfiltration from Vercoe Insurance Brokers, the 2023 Baden municipal data breach, and the 2025 Harrods intrusion attempt. Collectively, these activities illustrate that DragonForce blends financially motivated ransomware with politically driven disruption and data‑leak operations.
