logo

DragonForce Ransomware Breakdown and Decryptor for ESXi & Windows

ID: 1caef3bb-36cc-5506-924e-9c88a1540e13

STIX ID: report--1caef3bb-36cc-5506-924e-9c88a1540e13

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-01-14

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

This report analyzes the DragonForce ransomware RaaS: its recruitment and affiliate model, strong code similarity to LockBit 3.0 and Conti, operational activity including a Data Leak Site listing multiple victims, technical encryption details (per‑file ChaCha8 with RSA‑4096 metadata), SMB/ESXi targeting, and the recovery opportunity presented by victim‑bound Windows and ESXi decryptors obtained by researchers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.