DragonForce Ransomware Breakdown and Decryptor for ESXi & Windows
ID: 1caef3bb-36cc-5506-924e-9c88a1540e13
STIX ID: report--1caef3bb-36cc-5506-924e-9c88a1540e13
Feed Name: GBHackers
Threat Score
This report analyzes the DragonForce ransomware RaaS: its recruitment and affiliate model, strong code similarity to LockBit 3.0 and Conti, operational activity including a Data Leak Site listing multiple victims, technical encryption details (per‑file ChaCha8 with RSA‑4096 metadata), SMB/ESXi targeting, and the recovery opportunity presented by victim‑bound Windows and ESXi decryptors obtained by researchers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
