BushidoUK ToolMatrix CommunityReports: CR-022-DRAGONFORCE-FEB-2026

Fecha
18 Jun 2026
Actor
bushidouk
Tipo
Report
Pais
United Kingdom
Sector
Defense
Confianza
high
93
Prioridad analitica
Alta

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

7IOCs
1TTPs
bushidoukActor
United KingdomPais
Executive Summary
Recurso del BushidoUK Ransomware Tool Matrix - CommunityReports.

Key Points

  • Source: CommunityReports/CR-022-DRAGONFORCE-FEB-2026.md
  • BushidoUK Tool Matrix

CommunityReports: CR-022-DRAGONFORCE-FEB-2026.md

Recurso del BushidoUK Ransomware Tool Matrix - CommunityReports.

Community Report Template 022 - DragonForce February 2026

Contributor Details

- Real Name: N/A

- Online Handle / Links to profiles: Discord ap_2600

- Employer: Private, DFIR role

- Affiliations: Curated Intelligence, Ransom-ISAC

---

Adversary

- Named adversary: DragonForce

---

Incident Details

- Time of Incident: February 2026

- Victim Country: Australia

- Victim Size: 10-50

---

Observed Tools

| Discovery | RMM Tools | Defense Evasion | Credential Theft | OffSec | Networking | LOLBAS | Exfiltration |

|---|---|---|---|---|---|---|---|

| SoftPerfect netscan | | Windows Defender Real-time Protection disabled | | PsExec (PSEXESVC.exe) | | RDP (External Remote Services) | |

---

Indicators of Compromise (IOCs)

``

IP Addresses:

- 91.215.85.8 - RU - Prospero Ooo (AS200593) - initial RDP source

- 91.202.233.99 - TM - Prospero Ooo (AS200593) - RDP source

- 91.92.242.176 - NL - Omegatech LTD (AS202412) - RDP source

Filenames / Paths:

- C:\Users\REDACTED\Desktop\App\netscan.exe (SoftPerfect netscan - network discovery)

- C:\Users\REDACTED\Desktop\df.exe (DragonForce payload)

- C:\Users\REDACTED\Documents\df.exe (DragonForce payload)

- %SystemRoot%\PSEXESVC.exe (PsExec service for lateral movement)

Defender Signature:

- Ransom:Win32/DragonForce.C!MTB

Notable Behaviour:

- Initial Access via public-facing RDP (TA0001/T1133)

- PsExec lateral movement (T1021.002)

- Internal RDP lateral movement (T1021.001)

`

---

#### Any Related Sources

| Date Published | Report |

|---|---|

| N/A | https://www.softperfect.com/products/networkscanner/ |

---

#### Summary Diagram

`mermaid

flowchart TD;

A[DragonForce] -->|target| B(Geo: Australia

Size: 10-50 Employees);

B --> C{Tools};

C -->|Discovery| D[SoftPerfect netscan];

C -->|Defense Evasion| F[Defender disabled];

C -->|OffSec| H[PsExec];

C -->|LOLBAS| J[RDP / External Remote Services];

``

Referencias

Diamond Model

Adversary
bushidouk
Ver perfil →
Victim
BushidoUK ToolMatrix CommunityReports: CR-022-DRAGONFORCE-FEB-2026
United Kingdom
Capability
Report
1 TTPs MITRE
Infrastructure
91.215.85.8
91.202.233.99
91.92.242.176
www.softperfect.com

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
IP 91.215.85.8 Extraido del contenido VT OffSec SOCRadar
IP 91.202.233.99 Extraido del contenido VT OffSec SOCRadar
IP 91.92.242.176 Extraido del contenido VT OffSec SOCRadar
File PSEXESVC.exe Artefacto observado VT OffSec SOCRadar
File netscan.exe Artefacto observado VT OffSec SOCRadar
File df.exe Artefacto observado VT OffSec SOCRadar
Domain www.softperfect.com Extraido del contenido VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor bushidouk en el blog → Ver bushidouk en IntelTracker → Fuente OSINT: github.com→ Fuente OSINT: github.com → Buscar bushidouk en APTTrail → Repositorio APTTrail → Mas incidentes en United Kingdom → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes