dreamfyre Ransomware Group
Ransomware group profile
5Victims
Description
No description available for this group.
Industries
Threat Level & Status Breakdown
For dreamfyre · Based on incidents in selected period
0.4threat level
Claimed100.0%5
First seenJun 2026
Last seenJun 2026
Avg ransom—
Payment rate—
Recent activity
Monthly attack count for dreamfyre in the selected period
5Total attacks
5peak in Jun
5avg / month
No intelligence data for this group.
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for dreamfyre
Defense Evasion
T1562
Impair Defenses
Execution
T1059
Command and Scripting Interpreter
Impact
T1486
Data Encrypted for Impact
T1490
Inhibit System Recovery
Lateral Movement
T1021
Remote Services
T1021.001
Remote Desktop Protocol
Other
T1040
T1040
T1210
T1210
Persistence
T1078
Valid Accounts
T1547
Boot or Logon Autostart Execution
Victims(5)
| Company | Country | Status | Discovered | |
|---|---|---|---|---|
| Polatli | Turkey | Claimed | about 1 month ago | |
| Yapi_yatirim | Turkey | Claimed | about 1 month ago | |
| Online_satis | United States | Claimed | about 1 month ago | |
| Rheinfrucht-naturlink documents | Germany | Claimed | about 1 month ago | |
| Göknur Gıda İş Süreçleri (Çağlar Doğru) | Turkey | Claimed | about 1 month ago |
Affected countries(3)
Countries where this group has been reported to target or leak victims.