logo

Researchers Breakdown DragonForce Ransomware Along with Decryptor for ESXi and Windows Systems

ID: 7c1b3946-7d96-5daa-b10f-facd105b5b1d

STIX ID: report--7c1b3946-7d96-5daa-b10f-facd105b5b1d

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-14

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

DragonForce is a Ransomware-as-a-Service active since December 2023 that leverages leaked LockBit/Conti code and common post-exploitation tooling (Cobalt Strike, SystemBC) to move laterally and encrypt both Windows endpoints and VMware ESXi virtual disks. The malware uses ChaCha8 plus RSA-4096 for encryption, supports configurable modes (local, network, mixed) and partial/chunked encryption for speed, leaves .RNP/.RNP_esxi artifacts and metadata (build_key), and researchers have produced working decryptors for both Windows and ESXi, improving recovery prospects for some victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.