Analysis of a 32-bit Windows DragonForce ransomware payload shows the ransomware-as-a-service cartel preparing its runtime environment, decrypting embedded configuration and strings, inventorying the host, and writing encrypted activity logs. The malware attempts to stop selected security, backup, database, and productivity processes, then deletes Volume Shadow Copies through WMI and WMIC to impede recovery.
DragonForce identifies local drives and reachable SMB shares using the existing IPv4 ARP cache and share enumeration, then encrypts local and network files concurrently. It uses unique ChaCha20 material per file, protects that material with an embedded 4096-bit RSA public key, appends encryption metadata, and marks affected files with the .df_win extension; it also drops a ransom note and changes file icons and desktop wallpaper. While the note claims data theft, the observed sample showed no data-exfiltration or separate upload capability.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
DragonForce restructured as a ransomware cartel in March 2025, offering white-label backend infrastructure that enabled affiliates to operate under their own brands.
DragonForce first surfaced in mid-to-late 2023, initially presenting itself as a hacktivist collective.
Analysis of a 32-bit DragonForce Windows payload found that it inventories hosts, attempts to terminate security and business processes, deletes Volume Shadow Copies, and enumerates local drives and SMB shares through existing ARP-cache entries. The sample concurrently encrypts local and network files with per-file ChaCha20 material protected by an embedded 4096-bit RSA key, appends a .df_win extension, and drops a cartel ransom note; the observed execution did not show data exfiltration or a separate upload channel.
The operation moved away from its apparent hacktivist persona and adopted a profit-driven ransomware model. Its payload lineage included code based first on leaked LockBit 3.0 source and later on the leaked Conti builder.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.