The DragonForce ransomware group is chaining multiple SimpleHelp vulnerabilities to breach systems, steal sensitive files, and deploy an encryptor. DragonForce has been rather active in recent times. In late April 2025, it was reported the group had introduced a new business model to the ransomware scene, one which involves cooperating with other gangs. Apparently, the group was seen offering a white-label affiliate model, allowing others to use their infrastructure and malware while branding attacks under their own name.With this model, affiliates won’t need to manage the infrastructure and DragonForce will take care of negotiation sites, malware development and data leak sites. Do you think that it is impossible to be safe on the internet ?

