Quick Summary
AllegedExecutive Summary
Isegen South Africa (Pty) Ltd, an energy company based in South Africa, was listed on the dragonforce ransomware group’s dark web portal on July 15, 2026. This listing was identified by SOCRadar’s Dark Web Monitoring service. Operating within the energy sector, Isegen’s South African origin and industry place it geographically and sectorally outside the typical targeting pattern of dragonforce, which has predominantly focused on US and European victims in recent activities. In the 60 days leading up to this listing, dragonforce claimed 78 other victims, positioning it as a highly active threat actor. The group has shown a clear preference for the business services, manufacturing, and technology sectors, with a strong concentration of victims in the United States, United Kingdom, and Germany. Given Isegen’s divergence from the group’s usual profile, its closest parallels among recent victims include STEP Oiltools, Stephens Precision, Shillen Mackall & Seldon, and Hughes Atwood & Mullaly pllc, which represent a broader spectrum of dragonforce targets rather than direct sectoral or geographic matches.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry revealed a potential exposure linked to the isegen.co.za domain. The query identified five corporate usernames associated with the isegen.co.za domain on third-party services. Notably, no employee credentials were found on internal systems, nor were any third-party users identified on organization-owned URLs. Additionally, no identity, mail, or VPN endpoints were flagged during the telemetry scan. The observed pattern suggests a risk of workstation compromise, with one corporate account appearing in four records across three distinct log dates, and a second account appearing separately. This profile is consistent with the compromise of at least one, and potentially two, employee endpoints via infostealer malware. The identified exposure appears to have persisted without timely credential rotation, with logs showing a freshness window from November 2025 to February 2026. For ransomware groups like dragonforce, credentials harvested by infostealers represent a common initial access vector. Threat actors or initial access brokers often source these logs from underground forums, validate the corporate credentials, and then use them to gain access to systems via platforms such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While the current stealer-log findings do not conclusively confirm that these specific credentials were used in an intrusion event by dragonforce, the recurrence of corporate identities in stealer logs over an extended period is a strong indicator of the type of access that these actors exploit. CTI teams should investigate the affected endpoints and accounts as potential entry points, and prioritize credential rotation and endpoint forensics for the identified credentials.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.