DRAGONFORCE

RANSOMWARE

Confirmed CVEs (10)

Exploited by this group as confirmed by threat intelligence sources.

CVE-2021-44228 CRITICAL Apache Software Foundation Apache Log4j2 10.0 CVE-2024-21762 CRITICAL Fortinet FortiProxy 9.8 CVE-2024-55591 CRITICAL Fortinet FortiOS 9.8 CVE-2024-40766 CRITICAL SonicWall SonicOS 9.8 CVE-2024-21887 CRITICAL Ivanti ICS 9.1 CVE-2024-21893 HIGH Ivanti ICS 8.2 CVE-2023-46805 HIGH Ivanti ICS 8.2 CVE-2024-21412 HIGH Microsoft Windows 11 version 21H2 8.1 CVE-2024-57727 HIGH SimpleHelp SimpleHelp 7.5 CVE-2024-57728 HIGH SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user. 7.2

Predicted CVEs (90) CORRELATION

How does prediction work?

Predicted CVEs are identified through automated correlation using multiple sources: vendor/product profiles historically targeted by the group (MITRE ATT&CK), attack chain patterns (KEV + TTPs), threat intelligence (MISP, STIX), and AI analysis. These CVEs have not been confirmed as exploited by this specific group, but have a high probability of being targets based on the actor's operational profile.

CVE-2021-44228 CRITICAL Apache Software Foundation Apache Log4j2 predicted 10.0 CVE-2025-32433 CRITICAL erlang otp low 10.0 CVE-2024-3400 CRITICAL Palo Alto Networks PAN-OS predicted 10.0 CVE-2020-2021 CRITICAL Palo Alto Networks PAN-OS predicted 10.0 CVE-2026-48558 CRITICAL SimpleHelp predicted 10.0 CVE-2025-20337 CRITICAL Cisco Identity Services Engine Software low 10.0 CVE-2025-55182 CRITICAL Meta react-server-dom-webpack predicted 10.0 CVE-2026-20131 CRITICAL Cisco Secure Firewall Management Center (FMC) predicted 10.0 CVE-2026-20079 CRITICAL Cisco Secure Firewall Management Center (FMC) low 10.0 CVE-2025-55182 CRITICAL Meta react-server-dom-webpack low 10.0 CVE-2024-57726 CRITICAL SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role. predicted 9.9 CVE-2024-57726 CRITICAL SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role. high 9.9 CVE-2024-36401 CRITICAL geoserver low 9.8 CVE-2020-12812 CRITICAL Fortinet FortiOS predicted 9.8 CVE-2023-22527 CRITICAL Atlassian Confluence Data Center predicted 9.8 CVE-2023-22518 CRITICAL Atlassian Confluence Data Center predicted 9.8 CVE-2023-22515 CRITICAL Atlassian Confluence Data Center predicted 9.8 CVE-2023-46604 CRITICAL Apache Software Foundation Apache ActiveMQ predicted 9.8 CVE-2022-26501 CRITICAL Veeam Backup & Replication predicted 9.8 CVE-2024-40711 CRITICAL Veeam Backup and Recovery predicted 9.8 CVE-2025-22457 CRITICAL Ivanti Connect Secure predicted 9.8 CVE-2025-31324 CRITICAL SAP_SE SAP NetWeaver (Visual Composer development server) predicted 9.8 CVE-2026-104286 CRITICAL Fortinet FortiMail predicted 9.8 CVE-2024-0012 CRITICAL Palo Alto Networks Cloud NGFW predicted 9.8 CVE-2024-4577 CRITICAL PHP Group PHP predicted 9.8 CVE-2020-5135 CRITICAL SonicWall SonicOS predicted 9.8 CVE-2024-53704 CRITICAL SonicWall SonicOS predicted 9.8 CVE-2024-40766 CRITICAL SonicWall SonicOS predicted 9.8 CVE-2026-1731 CRITICAL BeyondTrust Remote Support(RS) & Privileged Remote Access(PRA) low 9.8 CVE-2023-22527 CRITICAL Atlassian Confluence Data Center low 9.8 CVE-2025-53770 CRITICAL Microsoft SharePoint Enterprise Server 2016 low 9.8 CVE-2025-3248 CRITICAL langflow-ai langflow predicted 9.8 CVE-2024-55591 CRITICAL Fortinet FortiOS predicted 9.8 CVE-2025-53770 CRITICAL Microsoft SharePoint Enterprise Server 2016 predicted 9.8 CVE-2024-4577 CRITICAL PHP Group PHP low 9.8 CVE-2024-40711 CRITICAL Veeam Backup and Recovery low 9.8 CVE-2024-0012 CRITICAL Palo Alto Networks Cloud NGFW low 9.8 CVE-2024-50603 CRITICAL Aviatrix Controller low 9.8 CVE-2026-1731 CRITICAL BeyondTrust Remote Support(RS) & Privileged Remote Access(PRA) predicted 9.8 CVE-2023-46604 CRITICAL Apache Software Foundation Apache ActiveMQ low 9.8 CVE-2024-21762 CRITICAL Fortinet FortiProxy predicted 9.8 CVE-2025-31324 CRITICAL SAP_SE SAP NetWeaver (Visual Composer development server) low 9.8 CVE-2025-3248 CRITICAL langflow-ai langflow low 9.8 CVE-2022-42475 CRITICAL Fortinet FortiProxy predicted 9.8 CVE-2025-54068 CRITICAL livewire low 9.8 CVE-2025-22457 CRITICAL Ivanti Connect Secure low 9.8 CVE-2026-0257 CRITICAL Palo Alto Networks Cloud NGFW predicted 9.1 CVE-2025-42999 CRITICAL SAP_SE SAP NetWeaver (Visual Composer development server) predicted 9.1 CVE-2024-21887 CRITICAL Ivanti ICS predicted 9.1 CVE-2021-45046 CRITICAL Apache Software Foundation Apache Log4j low 9.0 CVE-2021-45046 CRITICAL Apache Software Foundation Apache Log4j predicted 9.0 CVE-2025-0282 CRITICAL Ivanti Connect Secure predicted 9.0 CVE-2026-73570 HIGH Zimbra Collaboration low 8.9 CVE-2021-22899 HIGH Ivanti Pulse Connect Secure predicted 8.8 CVE-2025-33073 HIGH Microsoft Windows 10 Version 1507 low 8.8 CVE-2022-26500 HIGH Veeam Backup & Replication predicted 8.8 CVE-2025-49704 HIGH Microsoft SharePoint Enterprise Server 2016 predicted 8.8 CVE-2025-4428 HIGH Ivanti Endpoint Manager Mobile low 8.8 CVE-2021-22894 HIGH Ivanti Pulse Connect Secure predicted 8.8 CVE-2021-34527 HIGH Microsoft Windows 10 Version 1809 predicted 8.8 CVE-2023-46805 HIGH Ivanti ICS predicted 8.2 CVE-2024-21893 HIGH Ivanti ICS predicted 8.2 CVE-2025-24472 HIGH Fortinet FortiProxy predicted 8.1 CVE-2024-21412 HIGH Microsoft Windows 11 version 21H2 predicted 8.1 CVE-2021-1675 HIGH Microsoft Windows 10 Version 1809 predicted 7.8 CVE-2024-26169 HIGH Microsoft Windows 10 Version 1809 predicted 7.8 CVE-2022-30190 HIGH Microsoft Windows 10 Version 1809 low 7.8 CVE-2020-0787 HIGH Microsoft Windows predicted 7.8 CVE-2022-30190 HIGH Microsoft Windows 10 Version 1809 predicted 7.8 CVE-2023-28252 HIGH Microsoft Windows 10 Version 1809 predicted 7.8 CVE-2025-5777 HIGH NetScaler ADC predicted 7.5 CVE-2026-1603 HIGH Ivanti Endpoint Manager predicted 7.5 CVE-2020-3259 HIGH Cisco Adaptive Security Appliance (ASA) Software predicted 7.5 CVE-2024-57727 HIGH SimpleHelp SimpleHelp high 7.5 CVE-2023-27532 HIGH Veeam Backup & Replication predicted 7.5 CVE-2020-3259 HIGH Cisco Adaptive Security Appliance (ASA) Software low 7.5 CVE-2025-4427 HIGH Ivanti Endpoint Manager Mobile low 7.5 CVE-2025-5777 HIGH NetScaler ADC low 7.5 CVE-2023-36884 HIGH Microsoft Windows 10 Version 1809 predicted 7.5 CVE-2021-36942 HIGH Microsoft Windows Server 2019 predicted 7.5 CVE-2024-57727 HIGH SimpleHelp SimpleHelp predicted 7.5 CVE-2024-9474 HIGH Palo Alto Networks Cloud NGFW predicted 7.2 CVE-2021-22900 HIGH Ivanti Pulse Connect Secure predicted 7.2 CVE-2020-8243 HIGH Ivanti Pulse Connect Secure predicted 7.2 CVE-2020-8260 HIGH Ivanti Pulse Connect Secure predicted 7.2 CVE-2024-57728 HIGH SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user. predicted 7.2 CVE-2026-6973 HIGH Ivanti Endpoint Manager Mobile predicted 7.2 CVE-2024-57728 HIGH SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user. high 7.2 CVE-2024-38094 HIGH Microsoft SharePoint Enterprise Server 2016 predicted 7.2 CVE-2024-9380 HIGH Ivanti CSA (Cloud Services Appliance) predicted 7.2

ATT&CK Techniques (5)

T1204.002 User Execution Execution T1070.004 Indicator Removal: File Deletion Defense Evasion T1562.001 Impair Defenses: Disable or Modify Tools Defense Evasion T1083 File and Directory Discovery Discovery T1486 Data Encrypted for Impact Impact