Quick Summary
AllegedExecutive Summary
SOCRadar’s Dark Web Monitoring service identified Intron Technology Holdings, a technology company based in Taiwan, as a new victim on the DragonForce ransomware group’s leak portal. The listing was published on July 14, 2026. DragonForce has been actively targeting the technology sector, and Intron Technology Holdings fits this pattern, though it represents a departure from the group’s typical focus on Western countries. DragonForce’s recent activity over the preceding 60 days shows a pattern of targeting entities in business services, manufacturing, and technology, with a primary geographical concentration in the United States, followed by the United Kingdom and Germany. Intron Technology Holdings’ inclusion aligns with the ransomware group’s sector focus but expands their geographical scope to include East Asia.
Technical Analysis
Correlation with SOCRadar’s stealer-log telemetry revealed limited exposure for the intron-tech[.]com domain, with a single record indicating a corporate username found on a third-party SSO service. This was classified as a workstation-compromise signal rather than direct corporate intrusion, dated to mid-May 2026. While this single data point is not conclusive, it suggests a potential employee endpoint compromise. The typical DragonForce initial access vector involves exploiting infostealer-harvested credentials. These credentials are often sourced from underground marketplaces and used to access corporate systems like Microsoft 365, VPNs, or remote-access portals, paving the way for ransomware deployment. The discovered username surfacing on an SSO endpoint is a recognized indicator of workstation compromise, warranting further investigation, including an analysis of the affected endpoint for stealer activity, account rotation, and continuous monitoring.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.