Researchers Breakdown DragonForce Ransomware Along with Decryptor for ESXi and Windows Systems
ID: 7c1b3946-7d96-5daa-b10f-facd105b5b1d
STIX ID: report--7c1b3946-7d96-5daa-b10f-facd105b5b1d
Feed Name: cybersecurityNews.com
DragonForce is a Ransomware-as-a-Service active since December 2023 that leverages leaked LockBit/Conti code and common post-exploitation tooling (Cobalt Strike, SystemBC) to move laterally and encrypt both Windows endpoints and VMware ESXi virtual disks. The malware uses ChaCha8 plus RSA-4096 for encryption, supports configurable modes (local, network, mixed) and partial/chunked encryption for speed, leaves .RNP/.RNP_esxi artifacts and metadata (build_key), and researchers have produced working decryptors for both Windows and ESXi, improving recovery prospects for some victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
