{"id":9890,"date":"2026-01-15T10:04:11","date_gmt":"2026-01-15T10:04:11","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/15\/researchers-breakdown-dragonforce-ransomware-along-with-decryptor-for-esxi-and-windows-systems\/"},"modified":"2026-01-15T10:04:11","modified_gmt":"2026-01-15T10:04:11","slug":"researchers-breakdown-dragonforce-ransomware-along-with-decryptor-for-esxi-and-windows-systems","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/15\/researchers-breakdown-dragonforce-ransomware-along-with-decryptor-for-esxi-and-windows-systems\/","title":{"rendered":"Researchers Breakdown DragonForce Ransomware Along with Decryptor for ESXi and Windows Systems"},"content":{"rendered":"<p>    Researchers Breakdown DragonForce Ransomware Along with Decryptor for ESXi and Windows Systems<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>DragonForce is the latest ransomware brand to move from noisy forum posts to full RaaS operations, targeting both Windows and VMware ESXi environments. <\/p>\n<p>First seen in December 2023 on BreachForums, the group advertises stolen data and uses a dark web blog to pressure victims. The early leak post revealed the new cartel-style operation.<\/p>\n<p>The group built its payload from leaked <a href=\"https:\/\/cybersecuritynews.com\/lockbit-ransomware-hacked\/\" target=\"_blank\" rel=\"noreferrer noopener\">LockBit<\/a> 3.0 and Conti code, but tuned it for flexible, high-speed encryption across local disks and network shares. <\/p>\n<p>Operators usually gain access through exposed remote desktop servers, then use tools like <a href=\"https:\/\/cybersecuritynews.com\/hackers-delivering-cobalt-strike-beacon\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cobalt Strike<\/a> and SystemBC to move laterally before launching the ransomware. Impact ranges from encrypted file servers and virtual machines to stolen data prepared for public release.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgHVxOvhxsTCot2z47b06gl_zXvdmVtX7oTy-hhAAOfgl0gkePvvbwNR7lHYB37rnBaOSjMgj-TmXqEBAdHGy1MG2LMHmOyGvNylPBEhu954B8fh94x8RSezOE7Hyhf_QTmXPQ7mTcDxU7Xv_xx-We3RUr4RUukQc7NmNYZxfWLERvBx7UmlMvpl9idw4Y\/s16000\/Post%2520uploaded%2520to%2520BreachForums%2520%28Source%2520-%2520Medium%29.webp?ssl=1\" alt=\"Post uploaded to BreachForums (Source - Medium)\"><figcaption class=\"wp-element-caption\">Post uploaded to BreachForums (Source \u2013 Medium)<\/figcaption><\/figure>\n<\/div>\n<p>S2W analysts <a href=\"https:\/\/medium.com\/s2wblog\/detailed-analysis-of-dragonforce-ransomware-25d1a91a4509\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> a custom DragonForce build that hides nearly all strings with a home-grown deobfuscation routine and relies on ChaCha8 plus RSA-4096 for file encryption. <\/p>\n<p>Their research shows that command-line flags let affiliates choose local, network-only, or mixed modes, and even tune partial encryption ratios to speed up attacks. While its DLS shows the internal workflow from configuration decryption to process killing and file scrambling.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEia1OcWjUOMAhy_VqQ0iZoeXG7fNuF2S3qzP6SgvX_wflvTSYnxhUuLvo2SK0J_n8NwrXgqoN1YK0X40QKpyW-PhPCVvyUPTByEkTjeEm8BGn_paTor6q_w3XPud3CgpFwNbjFiSLxj0GpZwZl73s46ha5aOSs11UkljRwLwzdIESrWvz0yKzRQrUv3IJ4\/s16000\/DragonForce%25E2%2580%2599s%2520DLS%2520as%2520of%2520December%25202023%2520%28Source%2520-%2520Medium%29.webp?ssl=1\" alt=\"DragonForce\u2019s DLS as of December 2023 (Source - Medium)\"><figcaption class=\"wp-element-caption\">DragonForce\u2019s DLS as of December 2023 (Source \u2013 Medium)<\/figcaption><\/figure>\n<\/div>\n<p>During wider threat hunting, S2W researchers obtained a working decryptor for both Windows and ESXi systems, giving some victims a path to recovery without paying ransom. <\/p>\n<p>The Windows tool looks for files with the .RNP extension, while the ESXi version checks for .RNP_esxi files that also end with a specific eight-byte magic value called build_key.  Besides this it maps the full decryption chain from RSA key loading to metadata parsing and file restoration.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjJJwcobH-lztUz6qNFTJR72rt9YNJtFmVaE3HnrJ4wALDO4FRk7PhRkbW9mzl-dWrfHFJHEfE-7rP2NPyIe8mGfs5qPYk6gzNGltcmHycsGxzGAy3wtBGQdlYcxf3jHHaJQsWe4aIhtMTdiHJ-ypbN0hwqNgVpaoGuWzQ_RkxEq58xGEva_M3gIRyK_0w\/s16000\/DragonForce%2520%25E2%2580%2594%2520we%2520invite%2520you%2520to%2520join%2520our%2520family%2520%28Source%2520-%2520Medium%29.webp?ssl=1\" alt=\"DragonForce \u2014 we invite you to join our family (Source - Medium)\"><figcaption class=\"wp-element-caption\">DragonForce \u2014 we invite you to join our family (Source \u2013 Medium)<\/figcaption><\/figure>\n<\/div>\n<p>This complete technical breakdown gives defenders insight into DragonForce tools and recovery options.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-encryption-and-decryption-workflow\"><strong>Encryption and Decryption Workflow<\/strong><\/h2>\n<p>On execution, the <a href=\"https:\/\/cybersecuritynews.com\/everest-ransomware-gang-leak-site-hacked\/\" target=\"_blank\" rel=\"noreferrer noopener\">ransomware<\/a> first decrypts its internal configuration using ChaCha8, then reads options such as encryption mode and target path. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFJKTMojE9CyH13rqvOi6Hp-Wl5ymiDpqhTGID63tHdB1EE0owAGkx98kQNCzWJcKhU8_AobbLkUuIxLMsPtdVXGtK0gh0zoDP4PoYDH-Z9TUvfK8EXD6_suXP6XeNN3T98hp0_ndKCNzWWYGOhOqzewjqJoJlNcXhZqVhIwBXd1Q5UMjqGFhuPcO15q8\/s16000\/Post%2520announcing%2520the%2520migration%2520of%2520the%2520RansomHub%2520infrastructure%2520to%2520DragonForce%2520%28Source%2520-%2520Medium%29.webp?ssl=1\" alt=\"Post announcing the migration of the RansomHub infrastructure to DragonForce (Source - Medium)\"><figcaption class=\"wp-element-caption\">Post announcing the migration of the RansomHub infrastructure to DragonForce (Source \u2013 Medium)<\/figcaption><\/figure>\n<\/div>\n<p>A common command seen by S2W analysts is <code>dragonforce.exe -m net -p C:\\ -j 8<\/code>, which tells the malware to hit network targets under that path with multiple worker threads.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiGZhxegOjx1AEqz5EvFMPDSuHC3UTiF4AknepLNNxhmqg4a9RF3t4WCfsoL45YkiIcipPi_C5KkrY3OA5rGFSJaSlAgBF7SLlhjK1Vq3M0JHli_YAoGw0xxPGL_8uF1Bls212QawW90ZKp-JkD8fLCGZIPLPHNiSrhViowfXVuis-xSQJrzgJf4otmwII\/s16000\/DragonForce%2520Ransomware%2520Execution%2520Flow%2520%28Source%2520-%2520Medium%29.webp?ssl=1\" alt=\"DragonForce Ransomware Execution Flow (Source - Medium)\"><figcaption class=\"wp-element-caption\">DragonForce Ransomware Execution Flow (Source \u2013 Medium)<\/figcaption><\/figure>\n<\/div>\n<p>As it scans local and remote paths, <a href=\"https:\/\/cybersecuritynews.com\/dragonforce-ransomware-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">DragonForce<\/a> skips core system areas, then encrypts chosen files. For big virtual disk images it encrypts only chunks instead of the whole file to save time. <\/p>\n<p>At the end of each file it writes 534 bytes of metadata with an RSA-encrypted ChaCha8 key and nonce plus flags that store mode, ratio, and original size.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/researchers-breakdown-dragonforce-ransomware\/\">Researchers Breakdown DragonForce Ransomware Along with Decryptor for ESXi and Windows Systems<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/researchers-breakdown-dragonforce-ransomware\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers Breakdown DragonForce Ransomware Along with Decryptor for ESXi and Windows Systems DragonForce is the latest ransomware brand to move from noisy forum posts to full RaaS operations, targeting both Windows and VMware ESXi environments. First seen in December 2023 on BreachForums, the group advertises stolen data and uses a dark web blog to pressure [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-9890","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9890"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9890"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9890\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9890"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9890"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9890"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}