This week, Tanium’s Cyber Threat Intelligence (CTI) team examines DragonForce, a ransomware-as-a-service (RaaS) group that has become highly adaptable and dangerous. We also explore Qilin’s evolution into one of the most prolific global ransomware threats. Finally, we review an active campaign called Water Saci, which targets WhatsApp users.
DragonForce expands its influence
Trend Micro’s latest Ransomware Spotlight dives into DragonForce: a RaaS group first observed in 2023 and now considered one of the most aggressive players in the ecosystem. The group has evolved rapidly, moving from leaked builder-based attacks to a full affiliate-driven model.
Tracked as Water Tambanakua, DragonForce employs advanced evasion techniques such as bring your own vulnerable driver (BYOVD) and supports multi-platform attacks across Windows, Linux, ESXi, and NAS. It leverages multivariant payloads, reusing leaked LockBit and Conti builders instead of relying on a single ransomware family. Affiliates receive up to 80% of ransom proceeds, along with tools for attack management and customization.
In 2025, DragonForce rebranded as a ransomware cartel, encouraging affiliates to build their own brands while using shared resources. In June 2025, the group was linked to high-profile U.K. retail breaches. By August, it introduced a data analysis service that creates tailored extortion materials, such as call scripts and pseudo-legal reports, targeting organizations with annual revenues of at least $15 million.
Key trends and targets
Trend Micro determined that DragonForce has impacted the United States more than any other country. The most targeted sectors include manufacturing, construction, and IT. Victims range from small businesses to large enterprises, reflecting the group’s opportunistic approach.
DragonForce timeline
- 2023: Initial attacks using leaked LockBit 3.0 builder
- Mid-2024: Affiliate program launched; own ransomware released, followed by Linux variant
- June 2025: Linked to U.K. retail attacks
- March 2025: Shift to cartel model
- August 2025: Launch of data analysis service for affiliates
Infection chain and technical details
DragonForce exploits known vulnerabilities (e.g., Ivanti Connect Secure, Log4Shell) for initial access, often via Scattered Spider as an initial access broker. The ransomware can encrypt fixed, removable, and network drives and comes with a list of strings and extensions that it will avoid during encryption.
It also uses compromised admin accounts for persistence, token impersonation for privilege escalation, and tools like PsExec, WMI, and SimpleHelp RMM for lateral movement.
DragonForce is known to disable security tools and services for defense evasion, among other things, and to deploy credential dumping tools such as Mimikatz and LaZagne.
Analyst comments from Tanium’s Cyber Threat Intelligence team
The group’s shift from using leaked builders to creating its own ransomware and cartel-like structure shows a trend toward professionalization in the ransomware ecosystem, making attribution and disruption harder.
DragonForce is likely able to maintain its success and prominence because of its generous affiliate payouts and its use of techniques like BYOVD, which are typically observed in more advanced APT campaigns.
Qilin emerges as a top global ransomware threat
Cisco Talos is sharing details of the Qilin ransomware group’s transformation into one of the most prolific ransomware threats globally, disclosing more than 40 victims per month in the second half of 2025. The group operates under a RaaS model and employs double extortion, combining file encryption with public data leaks.
Qilin, formerly known as Agenda and active since July 2022, targets a wide range of countries while focusing heavily on the U.S., Canada, and the U.K., with additional impact in France and Germany. Qilin also targets multiple sectors, most notably manufacturing, followed by professional and scientific services, and wholesale trade.
In October, Qilin, DragonForce, and LockBit announced a strategic alliance. According to ReliaQuest, the collaboration will enable the groups to share techniques, resources, and infrastructure, strengthening each group’s capabilities.
Qilin tactics, techniques, and procedures (TTPs) explained
- Initial access: Cisco Talos assessed with moderate confidence that attackers likely abused leaked credentials to gain VPN access and possibly used AD Group Policy changes to enable RDP.
[Don’t let compromised credentials become an open door—learn how to harden Active Directory and stop attackers before they move laterally]
In one case, Cisco Talos identified several NTLM authentication attempts against the VPN just two weeks after credentials were exposed on the dark web. Multi-factor authentication (MFA) was not configured on the VPN. - Reconnaissance and discovery: The group has been seen executing
nltest.exeandnet.exeto enumerate domain controllers.
Cisco Talos also observed the actor assessing the privilege levels of various users by leveraging thewhoamicommand, along withtasklistandnetscanusage for process and network discovery. - Credential access and exfiltration: In the incidents analyzed by Cisco Talos, there was a password-protected folder containing tools that could be used for credential theft. Cisco Talos could not inspect every file in this folder, but believes it “suggests use of mimikatz, several password recovery utilities published by NirSoft, and custom script files.”
The registry was modified by enablingWDigest UseLogonCredential, which allowed plaintext credentials to be stored in memory. The data was later consolidated into a single text file and exfiltrated to an attacker-controlled SMTP server. - Artifacts of exfiltration: The attackers packaged stolen data using WinRAR and, during manual inspection, leveraged open-source tools like
mspaint.exe,notepad.exe, andiexplore.exeto inspect files and search for important information.
Most recently, the group has been using an open-source tool called Cyberduck to enable file transfers to cloud servers, often to Backblaze, using multipart upload settings to facilitate large-scale exfiltration and blend activity into legitimate traffic. - Privilege escalation and lateral movement: Stolen credentials enabled access to multiple IPs and network shares. Attackers modified firewall and RDP settings, added accounts to the local admin group, and created network shares granting full control. RMM tools observed include AnyDesk, ScreenConnect, and QuickAssist.
- Defense evasion: The actor used an obfuscated PowerShell to disable AMSI and TLS certificate validation, and enable restricted admin. The actor also attempted to disable EDR using tools like dark-kill and HRSword.
- Impact and inhibit recovery: Cisco Talos noted remote access tools like Cobalt Strike loader and SystemBC were deployed prior to ransomware execution.
- Qilin ransomware: Cisco Talos also detected the Qilin.B variant, notable for its dual encryptor strategy and advanced virtualization targeting. This variant supports deployment of two encryptors:
1.encryptor_1.exe, which spreads via PsExec across multiple hosts 2.encryptor_2.exe, which runs from a single system to encrypt numerous network shares
The variant also uses PowerShell commands to enumerate AD hostnames and install RSAT modules, aggressively targets ESXi environments by changing root passwords and disabling cluster protections, and modifies symbolic link settings via fsutil for broader file access.
The actor will then begin to move laterally, make changes to the Volume Shadow Copy Service, delete all shadow copies, and drop the ransom note in each encrypted folder. Each ransom note includes a Tor URL for negotiation and a unique victim ID embedded in the file extension, enabling access to a dedicated portal for payment and instructions.
Analyst comments from Tanium’s Cyber Threat Intelligence team
Qilin’s use of dual encryptors, cloud-based exfiltration, and remote access tools like AnyDesk and ScreenConnect reflects a mature and modular attack architecture. In addition, their ability to pivot across environments like Windows, ESXi, and the cloud demonstrates a deep understanding of enterprise infrastructure.
That said, it is unsurprising to see Qilin emerge as such an active and successful RaaS group. Their ability to disclose more than 40 victims per month is impressive and makes it a global and well-scaled operation.
Water Saci spreads via WhatsApp
Trend Micro recently published research about an active malware campaign referred to as Water Saci, which is targeting WhatsApp Web sessions through a self-propagating infection chain. The malware leverages script-based loaders (VBS + PowerShell) for fileless execution, hijacks browser sessions, and automates WhatsApp message delivery to spread base64-encoded malicious ZIP files with randomized filenames to all contacts and groups. It features advanced persistence and real-time command control via email, sharing tactics with the Coyote banking trojan.
Attack chain details
Trend Micro’s investigation revealed that Water Saci uses a highly structured infection chain initiated through WhatsApp Web. The campaign begins with suspicious file downloads and evolves into full session hijacking and automated propagation.
Key stages include:
- First stage: The attack starts when a victim downloads and extracts a ZIP archive named
Orcamento-2025*.zip. Inside is an obfuscated VBS downloader (Orcamento.vbs) that issues a PowerShell command to executetadeu.ps1directly in memory usingNew-Object Net.WebClient, enabling fileless execution and falling back to hardcoded defaults if C2 is unreachable. - Deceptive setup: The PowerShell script displays a banner claiming to be “WhatsApp Automation v6.0,” then establishes communication with its command-and-control (C2) infrastructure to retrieve target lists, message templates, and timing configurations. It creates a temporary workspace, downloads the WA-JS automation library from GitHub, and saves a malicious payload for later use.
- Browser hijacking: The malware checks the installed Chrome version, downloads the correct ChromeDriver, and installs the Selenium PowerShell module for automated browser tasks. It terminates Chrome processes, clears old sessions, and copies the victim’s Chrome profile (cookies and tokens) to bypass WhatsApp authentication without QR code scanning. Chrome is relaunched with automation flags designed to evade detection, and WA-JS is injected for full WhatsApp control.
- Propagation and exfiltration: With the hijacked session active, the malware harvests all WhatsApp contacts and exfiltrates them to the C2. It then distributes malicious ZIP files using base64 encoding, randomized filenames, and personalized messages, while attackers maintain real-time control to pause, resume, and monitor the campaign across infected machines.
SORVEPOTEL backdoor
The downloaded ZIP archive contains Orcamento.vbs, which is also known as the SORVEPOTEL backdoor. This component employs advanced anti-analysis techniques, including language checks to restrict execution to Portuguese systems, debugger detection, and a WMI-based mutex to enforce single-instance execution. If analysis tools are detected, the malware triggers a self-destruct routine.
Persistence is achieved through multi-vector mechanisms, including registry modifications and scheduled tasks using a dropped copy named WinManagers.vbs in C:\ProgramData\WindowsManager\.
Trend Micro believes the most sophisticated features of SORVEPOTEL is its dual-channel C2 architecture:
- Email-based retrieval: The malware uses IMAP connections to hardcoded terra.com.br email accounts to obtain C2 server URLs and configuration data. These emails contain multiple URL types (data endpoints, backup servers, and PowerShell payload delivery). Attackers later introduced MFA for these accounts, which added operational delays but improved security for their infrastructure.
- HTTP polling for live control: Once URLs are retrieved, the malware switches to aggressive HTTP polling for real-time command execution. This mechanism enables attackers to pause, resume, and coordinate botnet-like operations across infected machines, ensuring dynamic control and adaptability during campaigns.
Supported commands include system information collection, PowerShell execution, screenshot capture, process enumeration, file operations, and system power control (reboot/shutdown), among others.
Water Saci evolution and possible links to Coyote
Trend Micro’s analysis reveals that Water Saci shares significant technical and operational similarities with the Coyote banking trojan, suggesting both campaigns may originate from the same Brazilian cybercriminal ecosystem.
Key overlaps include:
- Use of WhatsApp Web session hijacking for self-propagation
- Browser automation via ChromeDriver and Selenium, combined with WA-JS injection
- Advanced anti-analysis techniques such as Portuguese language checks and debugger detection
- Persistent foothold through registry edits, scheduled tasks, and dropped scripts
These overlaps highlight a broader trend: threat actors transitioning from noisy, compiled payloads to stealthy, script-driven attacks that exploit legitimate browser profiles and messaging platforms.
Analyst comments from Tanium’s Cyber Threat Intelligence team
The shift to WhatsApp Web as an infection vector highlights a significant evolution in social engineering tactics. Threat actors are now leveraging trusted communication platforms to bypass traditional email-based defenses and exploit user familiarity.
The campaign’s use of fileless execution and real-time control capabilities also makes it more difficult to detect and contain. This threat is worth keeping an eye on, especially given its evolution and latest capabilities.
Do you have insight into these stories that you want to share? Head over to Tanium’s discussion forum to start a conversation.
For further reading, catch up on our recent cyber threat intelligence roundups.
