RANSOMWARE VICTIMDUPLICATE CLAIM

SERAPHITA GmbH

seraphita.ch
dragonforce📍 Germany (DE)📅 October 20, 2025
1
linked CVEs
8
same group

Attack Intelligence

SERAPHITA GmbH was compromised in a ransomware attack attributed to dragonforce in October 2025. The organization, operating in an undisclosed sector in Germany, was added to the group's data leak site as part of an extortion campaign.

dragonforce operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

Tax Return February 2025 Good preparation will save time and save time for a transplant. Would you like to prepare the following documents: - latest tax return - last final assessment order - Salary certificate (including additional earnings) - Balance sheets and income statement for self-employment - Certificate from the Unemployment Insurance Fund (daily allowance) - Reference pensions and pensions (AHV/IV, pension benefits, lifetime pensions, etc.) - Certificates of disability compensation (military, sick leave, accidents or unemployment benefits) - Annual report including VAT on Interest loans and expenses (bank, postal, etc.) - Catalog of securities of custodian banks, as well as reports on the purchase and sale of securities (including invoices). Dividend loans) - Receipts for payment of interest on the debt (receipts are required) - Rental income or cost of ownership-Disposal - Supporting documents on the conversion and maintenance of the property - A certificate of any extraordinary contributions to Pension Fund - Certificate of deposits Column 3 a (supporting documents required) - Supporting documents on travel expenses for work / meals outside the home - Supporting documents on professional expenses (work tools, technical literature, etc.)

Intelligence correlations link this incident to 1 vulnerability(ies) including CVE-2025-5777, which may have been leveraged as initial access vectors or for lateral movement.

Additional Details

Correlated Vulnerabilities (1)

Other Victims — dragonforce (8)

Quick Facts

CountryGermany (DE)
Attack DateOct 20, 2025
Domainseraphita.ch
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

dragonforce
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.