M&S Hackers: Cybercrime Group Conflict
Ransomware Rivalry: DragonForce and RansomHub Conflict Raises Cyberattack Risk
Table of Contents
The murky world of ransomware is experiencing a power struggle, with a dispute between hacking groups DragonForce and RansomHub sparking concerns of increased cyberattacks and even double extortion attempts on victims. This internal conflict within the “extortion ecosystem” highlights the volatile and ruthlessly competitive nature of cybercrime, and poses a growing threat to businesses and organizations worldwide.
The Emerging Conflict: DragonForce vs. RansomHub
DragonForce, a relatively new player identified in August 2023, quickly gained notoriety by listing 82 victims on its dark-web site within a year. RansomHub, emerging around the same time, boasts a substantially larger portfolio, claiming approximately 500 victims in 2024.Recent activity suggests DragonForce may be attempting to poach affiliates from RansomHub, and has also been linked to attacks targeting the pages of rival groups like BlackLock and Mamona.
Genevieve Stark, head of cybercrime analysis at Google Threat Intelligence Group, warns that this instability carries significant risk.”Instability within the extortion ecosystem can have serious implications for ransomware and data theft extortion victims,” she stated. The core issue isn’t simply competition; it’s the breakdown of established, albeit illicit, partnerships.
The Threat of Double Extortion
While uncommon, the potential for “double extortion” – where a victim is targeted by multiple ransomware groups – is a very real consequence of this fallout. A recent case involving UnitedHealth Group exemplifies this danger. Last year,after an initial $22 million ransom payment,affiliate hacker group Notchy attempted to extort a second payment. This occurred because Notchy’s original Ransomware-as-a-Service (RaaS) partner disappeared to avoid sharing the profits.
According to cybersecurity experts familiar with the UnitedHealth hack, multiple extortion attempts are not unheard of, but subsequent demands often lack credibility.However, Rafe pilling, director of threat intelligence at Sophos, paints a more alarming picture. “In a worst-case scenario, the conflict between DragonForce and RansomHub could see them both target the same victim in a battle for business,” he explains. “Cybercriminals are a ruthless bunch,and a betrayal between partners can result in a situation where the victim gets extorted twice.”
The Rising Cost of Cybercrime
This internal strife occurs against a backdrop of escalating cybercrime costs. Cybersecurity Ventures estimates the global financial impact will reach a staggering $10 trillion in 2025 – a dramatic increase from the $3 trillion recorded in 2015. This surge is driven by hacker groups’ relentless pursuit of maximizing profits through increasingly elegant attacks.The volatile nature of these groups and their shifting allegiances further complicate defense strategies.jake Moore,global cybersecurity adviser at ESET,emphasizes the chaotic environment. “Remember this is a Wild West, lawless environment where normal competition rules simply do not apply.” Customary cybersecurity approaches may prove inadequate in the face of such unpredictable behavior.
preparing for Increased Risk
Organizations must prioritize robust cybersecurity measures and incident response plans. This includes:
Enhanced Threat Intelligence: Staying informed about emerging threats and the tactics, techniques, and procedures (TTPs) of ransomware groups like DragonForce and RansomHub. Stronger Access Controls: Implementing multi-factor authentication and least privilege access to limit the potential damage from a breach.
Regular Data Backups: Maintaining offline,immutable backups to ensure data recovery without paying a ransom.
Incident Response Planning: Developing and regularly testing a complete incident response plan to minimize downtime and data loss.
* Employee Training: Educating employees about phishing scams and other social engineering tactics used by cybercriminals.
Looking Ahead: A More Fragmented and Hazardous Landscape
The conflict between DragonForce and RansomHub is highly likely a harbinger of further fragmentation within the ransomware ecosystem. As groups rise and fall, and alliances shift, the threat landscape will become increasingly complex and unpredictable. Proactive threat intelligence, robust security measures, and a commitment to continuous improvement will be crucial for organizations to navigate this evolving danger and protect themselves from becoming the next victim. The “Wild West” of cybercrime is only becoming more lawless, demanding a more vigilant and adaptable defense.
