Quick Summary
AllegedExecutive Summary
DragonForce ransomware has targeted Atcom, a telecommunication company based in China. The incident was reported on the group’s dark web portal on July 14, 2026, and flagged by SOCRadar’s Dark Web Monitoring service. Telecommunication companies are considered high-value targets due to their critical infrastructure and the significant amount of customer data they possess. This particular victim’s location in China represents a deviation from DragonForce’s typical targets in the United States, United Kingdom, and Germany, suggesting a broader operational scope for the group.
Technical Analysis
SOCRadar’s threat intelligence analysis found no direct correlation with stealer-log telemetry for atcomm[.]cn. However, this does not rule out compromise, as credentials might be exfiltrated via alternate corporate domains, personal email aliases, or through data feeds not covered by the analyzed dataset. DragonForce commonly gains initial access through credentials harvested by infostealers, which are then used to access corporate systems like Microsoft 365, VPNs, or remote access portals before deploying ransomware. The report emphasizes the importance of continued monitoring and proactive credential hygiene measures for organizations.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.