Full Report
A technical walkthrough from runtime preparation and network-share discovery to concurrent file encryption DragonForce is a Ransomware-as-a-Service (RaaS) operation that first surfaced in mid-to-late 2023. It initially presented itself as a hacktivist collective before shifting to a profit-driven model. Early payloads were built on leaked LockBit 3.0 source code and later supplemented with code derived […] The post Inside DragonForce: How a Ransomware Cartel’s Payload Actually Runs appeared first on Seqrite Labs.
Analysis Summary
# Tool/Technique: DragonForce Ransomware
## Overview
DragonForce is a Ransomware-as-a-Service (RaaS) operation that emerged in late 2023. Originally posing as a hacktivist collective, it transitioned into a profit-driven "ransomware cartel" model. The malware is designed to perform large-scale concurrent encryption of local and network-attached storage, utilizing leaked source code from LockBit 3.0 and Conti to enhance its capabilities.
## Technical Details
- **Type:** Malware Family (Ransomware-as-a-Service)
- **Platform:** Windows (x86/x64)
- **Capabilities:** Process termination, shadow copy deletion, ARP-based network discovery, SMB share encryption, ChaCha20/RSA encryption, desktop wallpaper/icon customization.
- **First Seen:** Mid-to-late 2023 (Restructured to Cartel model in March 2025).
## MITRE ATT&CK Mapping
- **TA0007 - Discovery**
- T1083 - File and Directory Discovery
- T1016 - System Network Configuration Discovery (ARP-based discovery)
- T1018 - Remote System Discovery
- **TA0005 - Defense Evasion**
- T1562.001 - Impair Defenses: Disable or Modify Tools (Process interference)
- T1027 - Obfuscated Files or Information (Affine transform string encoding)
- T1140 - Decompress/Decrypt Files or Information (ChaCha20 configuration decryption)
- **TA0040 - Impact**
- T1486 - Data Encrypted for Impact
- T1489 - Service Stop
- T1490 - Inhibit System Recovery (Shadow copy deletion via WMIC)
## Functionality
### Core Capabilities
- **Parallel Encryption Engine:** Uses a producer-consumer model where discovery threads feed local and network paths into queues for multiple worker threads to encrypt concurrently.
- **Hybrid Encryption:** Employs ChaCha20 for file encryption, with the per-file key material protected by a master RSA public key.
- **Network Propagation:** Scans the local network using ARP to identify active SMB targets and maps shares for encryption.
- **Persistence/Registry Modification:** Associates the `.df_win` extension with a custom icon in `HKEY_CLASSES_ROOT`.
### Advanced Features
- **String Obfuscation:** Uses a custom reversible affine transform `(7x + 0x6A) mod 127` to hide strings like API names and registry paths.
- **API Resolution Validation:** Manually resolves `LoadLibraryA` and `GetProcAddress`, verifying that jump targets fall within the sample's `.idata` section to detect hooking or redirection.
- **Encrypted Logging:** Maintains a detailed runtime log at `C:\Users\Public\log.log`, encrypted with ChaCha20, documenting host reconnaissance and encryption progress.
- **Restart Manager Integration:** Uses the Windows Restart Manager to unlock files currently in use by other applications.
## Indicators of Compromise
- **File Names:**
- `readme.txt` (Ransom note)
- `C:\Users\Public\log.log` (Encrypted log)
- `C:\Users\Public\icon.ico`
- `C:\Users\Public\wallpaper_white.png`
- **Registry Keys:**
- `HKEY_CLASSES_ROOT\.df_win`
- **Behavioral Indicators:**
- Execution of `WMIC.exe shadowcopy where "ID='<GUID>'" delete`.
- Termination of security and database processes (e.g., `MsMpEng.exe`, `sqlservr.exe`).
- High-volume ARP scanning followed by SMB (port 445) connectivity.
- **File Extension:** `.df_win`
## Associated Threat Actors
- **DragonForce (Ransomware Cartel):** Operates as a RaaS provider for various affiliates.
## Detection Methods
- **Signature-based:** Detection of the unique affine transform decryption routine or the specific RSA public key blob.
- **Behavioral detection:** Monitoring for rapid file renaming to `.df_win` and the use of `WMIC` to delete shadow copies.
- **Log Analysis:** Presence of the `log.log` file in the `Public` directory with a 16-byte plaintext header (build/instance keys).
## Mitigation Strategies
- **Prevention:** Implement robust EDR/AV solutions to block process termination attempts and unauthorized use of the Windows Restart Manager.
- **Hardening:** Disable or restrict `WMIC` and `vssadmin` access for standard user accounts to prevent shadow copy deletion.
- **Network Security:** Segment networks to limit the scope of ARP-based discovery and restrict SMB traffic to authorized administrative hosts.
- **Backups:** Maintain offline, immutable backups to facilitate recovery without paying the ransom.
## Related Tools/Techniques
- **LockBit 3.0:** Source code was used as a foundation for early DragonForce payloads.
- **Conti:** Code derived from the leaked Conti builder is integrated into newer variants.
- **ChaCha20/RSA:** Standard cryptographic primitives used similarly to other modern ransomware like Babuk or REvil.