GOLD FLAME
Objectives
Tools
SUMMARY
GOLD FLAME operates the DragonForce ransomware-as-a-service (RaaS) scheme. The group first emerged in August 2023 offering a traditional ransomware-as-a-service (RaaS) model that involved affiliates exfiltrating data, deploying the DragonForce-branded ransomware on victims’ networks, and then listing victims on the DragonForce leak site as part of their extortion strategy. In March 2025, the group announced the launch of a new 'white label' service. This was advertised as a distributed affiliate branding model that allows partners to leverage DragonForce’s infrastructure and ransomware tools while operating under their own names, with their own leak sites and branding. With this change of model came an aggressive campaign to garner attention, with DragonForce attacking rival groups such as Mamona and BlackLock with website defacements. The group were also in conflict with rival group RansomHub, which in the 12 months prior had listed the most victims of any ransomware group on their leak site. This conflict saw the RansomHub administrator admonish DragonForce on the Russian language RAMP forum in relation to their conduct, and ultimately resulted in the demise of the RansomHub brand. In April 2025, DragonForce made headlines when they claimed responsibility for a campaign targeting UK retailers.
お問い合わせ
お客様の組織が早急な支援を必要としている場合でも、インシデントの準備、対応、テストのニーズについて相談したい場合でも、以下からお問い合わせください。