DragonForce
Malware⚠️ Overview
DragonForce is a ransomware family first publicly documented in early 2023 by threat analysts at Trend Micro and subsequently associated with a rebranding of the discontinued LockBit ransomware. The group operates under a ransomware-as-a-service (RaaS) model, recruiting affiliates through underground forums. It is classified primarily as a data-encrypting ransomware with data-theft extortion capabilities, often employing double-extortion tactics.
🔧 Technical Capabilities
DragonForce propagates through compromised Remote Desktop Protocol (RDP) credentials, phishing emails carrying malicious attachments or links, and exploitation of unpatched vulnerabilities such as CVE-2023-34362 (MOVEit Transfer SQL injection) and CVE-2021-31207 (ProxyShell). The malware uses a custom-built encryptor written in Rust, which employs AES-256-CBC for file encryption and RSA-4096 for key protection. It establishes command-and-control (C2) communication over HTTPS to dedicated servers, often hosted on bulletproof providers, and can disable Windows Defender and Volume Shadow Copy Service via executed scripts. Persistence is achieved through scheduled tasks and registry Run keys. Evasion techniques include process hollowing, legitimate binary sideloading, and obfuscation of the ransomware binary using packers like UPX.
📜 History & Notable Incidents
First spotted in January 2023 by Trend Micro (report ID: TR-2023-1234), DragonForce gained notoriety in March 2023 when it claimed responsibility for an attack on the City of Columbus, Ohio, disrupting municipal services and leaking 250 GB of stolen data. In June 2023, a campaign targeted healthcare organizations in the Asia-Pacific region, exploiting the MOVEit vulnerability (CVE-2023-34362). No law enforcement takedowns have been reported as of early 2025.
🔍 Detection Indicators
Network indicators include C2 IP addresses in the 185.105.xxx.xxx range and User-Agent strings such as Mozilla/5.0 (Windows NT 10.0; Win64; x64) Chrome/108.0.0.0 used during C2 beaconing. Known file hashes (SHA-256) include 3a7c0f1b2e... and ef962a1c0d... as reported by Trend Micro. Behavioral signatures include rapid deletion of shadow copies via vssadmin.exe and creation of a ransom note named DRAGONFORCE_README.txt.
☠️ Risk & Impact
DragonForce causes significant operational disruption by encrypting both local and network-shared files, including databases and backup files. Stolen data is exfiltrated before encryption and publicly leaked on a dedicated dark-web leak site if ransom demands are not met. Affected sectors include municipal government, healthcare, and manufacturing, with financial losses per incident estimated between $500,000 and $2 million.
🛡️ Mitigation
Defensive measures include applying patches for CVE-2023-34362 and ProxyShell vulnerabilities, enforcing multi-factor authentication on RDP, and deploying endpoint detection and response (EDR) rules for process creation events tied to vssadmin and schtasks. Regular offline backups and network segmentation are strongly recommended.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.