Hacker 'turf war' unfolding as Russian DragonForce ransomware gang drama could lead to 'double extortions,' making life even worse for potential victims

laptop on fire
(Image credit: Shutterstock)

Ransomware is a powerful tool used by weak people to extract make-believe money, primarily used for dark web drug buys and Ponzi schemes, from organizations that haven't implemented proper security and backup protocols in the year 2025. It comes as no surprise, then, that drama between several "gangs" who rely on this involuntary encryption tool is reportedly set to make things even worse for potential victims.

The Financial Times today reported that DragonForce, "a group of largely Russian speaking cyber criminals behind a spate of high-profile attacks this year," has "begun a turf war with its rivals" that "could bring more hacks and further fallout for corporate victims." Why? Apparently, it's because a group called RansomHub "widened the services it offered and expanded its reach to attract more affiliate partners."

The experts who spoke to the Times about this spat are concerned that DragonForce and RansomHub will attempt to extort the same organizations to "one-up" each other. These so-called double extortions can make it even more difficult for ransomware victims to recover from an incident — especially if they simply cannot afford to pay more than one cybercriminal to regain access to their own information. (Hopefully.)

Google Threat Intelligence Group head of cybercrime analysis Genevieve Stark told the Times that "instability within the extortion ecosystem can have serious implications for ransomware and data theft extortion victims.” That's a somewhat curious take, however, given the relative instability of this "ecosystem" regardless of whether or not two of its members are engaging in a virtual scuffle over their illicit dealings.

Sophos noted in 2022 that the closure of the BlackMatter ransomware group hardly mattered: "Ransomware-as-a-service is simply the service. Affiliates who buy the service and do the actual hacking simply seek out new networks to affiliate with and continue with their crime sprees unabated. Meanwhile, the operators, or original creators, of the ransomware that 'closed,' will likely re-emerge under a new name."

Disputes between ransomware gangs have also historically led to in-fighting rather than worse outcomes for potential victims. The Financial Times said that DragonForce took down RansomHub's dark web site, for example, and the Conti ransomware group imploded after Russia invaded Ukraine in 2022 because it had members from both countries and they simply couldn't cooperate after the war began that February.

Perhaps the most well-known counterpoint is the double extortion of UnitedHealth Group. In that case, a ransomware affiliate called Notchy turned to RansomHub to continue extorting UHG subsidiary Change Healthcare even after it paid a $22 million ransom that was reportedly stolen by BlackCat / ALPHV as part of an exit scam. So organizations have been caught up in thief-on-thief drama before.

Here's to hoping any organizations DragonForce and RansomHub want to put through a similar ordeal respond like Welthungerhilfe, a German nonprofit that has refused to pay a ransom. Let the cybercriminals have their turf wars; the most important thing is that organizations refuse to play a part in the conflict themselves by giving these groups the funds they need to continue their shenanigans.

Follow Tom's Hardware on Google News to get our up-to-date news, analysis, and reviews in your feeds. Make sure to click the Follow button.

Nathaniel Mott
Freelance News & Features Writer

Nathaniel Mott is a freelance news and features writer for Tom's Hardware US, covering breaking news, security, and the silliest aspects of the tech industry.

  • Krasen007
    excuse me extract make-believe money?
    b it co i n is very real my friend... ( why is this censured? ?? ) ((is this why you said make-believe money?? are you internally censored?? )
    Reply
  • SomeoneElse23
    BTC is real, but it's not money.
    Reply
  • Notton
    Technically, no currency is real right now, they're all vibes based.
    crypto? digital vibes
    stocks? wallstreet bro vibes
    fiat currency? bankster vibes

    The only real currency is backed by gold.
    Reply
  • pmkoom
    This has to be written by a boomer...weak people and fake money? I say they are extremely powerful people and fake money I don't think so. Toms hardware wtfff
    Reply
  • circadia
    pmkoom said:
    This has to be written by a boomer...weak people and fake money? I say they are extremely powerful people and fake money I don't think so. Toms hardware wtfff
    in their defense, this article was written by a freelancer, so...

    and I wouldn't say ransomware groups are "powerful people", more like "knowledgeable people who end up commiting crime" or whatever.
    Reply