Quick Summary
AllegedExecutive Summary
STEP Oiltools, an energy organization based in Romania, has been identified as a victim by the DragonForce ransomware group. The incident was reported on July 12, 2026, via the group’s dark web leak portal, as detected by SOCRadar’s Dark Web Monitoring service. The listing indicates that STEP Oiltools operates within the Energy sector, placing it alongside other recent victims targeted by DragonForce. Over the preceding 60 days, DragonForce has claimed 67 victims, frequently targeting companies in Business Services, Manufacturing, and Agriculture and Food Production, with a geographical focus on the United States, the United Kingdom, and Germany. STEP Oiltools’s profile aligns with the typical targets of this ransomware group.
Technical Analysis
SOCRadar’s analysis of initial access vectors, using stealer-log telemetry, did not reveal any direct connections to STEP Oiltools’s domain (stepoiltools.com). However, the absence of such evidence does not preclude an attack. Credentials may have been compromised through alternative means, such as personal email aliases, or logged in feeds outside the analyzed dataset. It’s also possible that compromised credentials were used and rotated before being indexed by the telemetry. The report advises CTI teams to maintain vigilance and prioritize credential hygiene, as a null query result does not confirm the absence of a compromise, especially considering that infostealer-harvested credentials are a known initial access method for ransomware groups like DragonForce.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.