Skip to content
Group-IB — DragonForce Ransomware Group

Group-IB — DragonForce Ransomware Group

www.group-ib.com September 11, 2026

In this blog, we look at the DragonForce ransomware group, which poses a severe threat with two variants—a LockBit fork and a customized Conti fork with advanced features and SystemBC malware.

DragonForce is a Ransomware-as-a-Service operation that uses two main Windows ransomware variants: one based on LockBit 3.0 and another analyzed by Group-IB as a ContiV3-based build with added features such as BYOVD, scheduled-task persistence, and expanded encryption customization. Group-IB’s research also links DragonForce activity to SystemBC, Cobalt Strike, Mimikatz, and network-reconnaissance tooling used during real intrusions.

According to Group-IB’s Hi-Tech Crime Trends 2023/2024 Report , ransomware will have an increasingly significant impact in 2024 and beyond. Key trends driving this include the expansion of the Ransomware-as-a-Service (RaaS) market, the proliferation of stolen data on Dedicated Leak Sites (DLS) , and a rise in affiliate programs.

In this blog, we delve into the inner workings of the DragonForce ransomware group . Discovered in August 2023, DragonForce has been targeting companies in critical sectors using a variant of the leaked LockBit3.0 builder and, more recently, in July 2024, with their own ransomware variant.

What is DragonForce Ransomware?

DragonForce is a Ransomware-as-a-Service (RaaS) affiliate program that now uses 2 versions of ransomware to target its victims. Many DragonForce ransomware attacks are customized to each victim to maximize its impact. To do this, the threat actors can leverage tactics such as changing the filename extensions of encrypted files, and terminating specific processes and services. Its ransomware builder allows affiliates the capability to specify exactly which processes the ransomware should terminate, to ensure the successful encryption of all important data on the victim’s devices.

Based on the observations by Group-IB’s Threat Intelligence analysts, DragonForce advertises their ransomware on the dark web . It has a proprietary DLS that contains unique company IDs and leaked account details.

The operators of DragonForce utilize a double extortion technique, where they exfiltrate a victim’s sensitive data in addition to encrypting it. They then demand ransom payment from their victims in return for a decryptor, and the “promise” that their stolen data will not be released.. This dual-pronged approach of losing both access to their data as well as having their confidential information exposed adds significant pressure on the victim to comply with the attackers’ demands as there might be potential damage to their reputation, privacy, or business continuity if their data is made public.

From August 2023 to August 2024, DragonForce ransomware listed a total of 82 victims on their Dark Web site. Of these, 43 attacks occurred in the United States, making up 52.4% of the incidents. Other significant targets included the United Kingdom with 10 attacks (12.2%) and Australia with 5 attacks (6%).

Figure 1. Heatmap of targeted countries by DragonForce ransomware and its affiliates.

The manufacturing industry was the most targeted, with 12 attacks accounting for 14.6% of the total incidents. The Real Estate sector followed as the second most attacked, experiencing 11 incidents, which represents 13.4% of the total. The third most affected industry was Transportation, with 10 attacks, making up 12.2% of the total.

Figure 2. Number of attacks on industries by DragonForce and its affiliates.

Inside the belly of the beast

On 26 June 2024, a user with the handle “dragonforce” started promoting an affiliate program of the DragonForce Ransomware on the underground forum “RAMP”, which contained information on how its affiliates can earn 80% of the total ransom amount, as well as key features of its ransomware including client tracking, automated file delivery, secure access control, and support for extended detection and response (XDR) / endpoint detection and response (EDR) bypass, encryption, and SYSTEM impersonation, adding that comprehensive support services are also available to their affiliates.

Figure 3: Screenshot of a post by DragonForce promoting its ransomware-as-a-service on the RAMP forum.

Collaboration Invitation from DragonForce

DragonForce invites partners for collaboration! We are ready to welcome specialists from various fields, whether access specialists, pentesters, or pentesting teams.

Our infrastructure and tools

80% of your revenue (we only take 20%)

Advanced technologies

Full automation of all work processes

– Flexible tools for tracking client actions

– Automated file issuance

– Test decrypt function

Our panel is considered one of the best on the market. We have addressed all the shortcomings of other similar solutions and implemented them in DragonForce.

– Each partner receives a unique .onion address with a key

– Ability to create access for your team members

– Access rights management

– Decryption keys are removed from our servers after the payment period expires (time is set in the builder)

– Each team has a Chief Administrator

– Employees with different access levels (set by the chief administrator)

– Files are stored on our secure servers

– Automatic file size determination

– Ability to automatically issue files to clients

– Hidden publications available via unique link

– Attachment of screenshots, audio, and chats

– Scheduling publication times

– Tracking the number of views and clicks

– Distributed file storage in different locations worldwide

Locker (Windows, ESXi, NAS):

– Solutions integrated into the locker itself, bypassing XDR/EDR; all you need is the crypt (driver)

– “Scheduled job” function for running processes at a specific time (UTC format)

– Different file encryption methods, various approaches

– SYSTEM impersonation

– And much more, the locker is continuously being improved.

(We strive to listen to our partners and implement additional features in our locker.)

– Call service (for an additional fee or percentage)

– Support and accompaniment of large projects

Please note that I may request you to pass verification through the RAMP platform. If there are doubts your identity, I may refuse cooperation. Please respect both your time and mine. Thank you!

Tox: 1C054B722BCBF41A918EF3C485712742088F5C3E81B2FDD91ADEA6BA55F4A856D90A65E99D20

Blog: (

01101111 01101110 01101100 01111001 00100000 00110011 00100000 01110011 01110100 01100101 01110000 01110011 00100000 01110100 01101111 00100000 01100100 01100101 01100011 01110010 01111001 01110000 01110100 00101110 00101110 00101110

Figure 4. Screenshot of the user profile ‘dragonforce’ on the RAMP forum.

On July 4, DragonForce announced on the RAMP forum that they now only accept affiliates who have pre-acquired access, complete proof of their access, and have already exfiltrated victim data.

Figure 5. Screenshot of DragonForce’s post dated 4 July 2024.

We appreciate your consideration of our RaaS and want to communicate the importance of careful candidate selection. In order to start working with us, we ask you to complete the following steps:

Prepare a target with an income of $5,000,000 US dollars and above.

Send us information your zoominfo target .

Provide files using any storage location convenient for you (for example, mega.co.nz or SSH).

The files must match the zoominfo you provided .

We ask you to us in advance to agree on all the details so that the process goes as smoothly as possible and without delays. This will allow you to access our RaaS faster .

Tox: 1C054B722BCBF41A918EF3C485712742088F5C3E81B2FDD91ADEA6BA55F4A856D90A65E99D20

Sincerely, 01101111 01101110 01101100 01111001 00100000 00110011 00100000 01110011 01110100 01100101 01110000 01110011 00100000 0 1110100 01101111 00100000 01100100 01100101 01100011 01110010 01111001 01110000 00101110 00101110 01110100 00101110

How does the DragonForce affiliate program work?

DragonForce launched its affiliate program publicly in June 2024, offering 80% of ransom proceeds and access to a panel where affiliates can configure ransomware builds, manage victims, publish leaks, and coordinate team access. Group-IB also observed the group restricting participation to affiliates that already had proven access and exfiltrated data, which suggests a preference for more mature intrusion partners.

The introduction of the affiliate program allows other cybercriminals to join forces, significantly expanding the group’s reach and potentially leading to a surge in ransomware infections.

In a private conversation on Tox, Group-IB’s Threat Intelligence specialists obtained the following information from the attacker:

Each affiliate has a unique .onion address, and a new profile needs to be created for each team member to grant them their own access.

The affiliates have two ransomware variants for Windows: one of their own creation and a LockBit variant that allows individuals coming from LockBit to adapt quickly. According to DragonForce, their ransomware can bypass XDR and EDR.

During the course of our research, Group-IB’s Threat Intelligence specialists were able to obtain access to DragonForce’s panel.

The Affiliates’ panel of DragonForce ransomware group has the following sections:

The “Clients” section contains information the companies attacked (victims), and includes details such as the amount of the ransom, status of ransom, creator of the builder, ID of the client, DLS, size of the leak, clients’ status step (paid, or negotiation in the process), last seen, and if the leak has been published.

Figure 7. A screenshot of the “clients” section of the DragonForce affiliates’ panel

This section allows affiliates to build samples of the DragonForce ransomware with different configurations.

Figure 8. Screenshot of the LockBit version of the DragonForce ransomware.

With the LockBit version of the DragonForce ransomware, affiliates can configure the following parameters:

Test decryption (enable or disable)

Time range for ransom payment and use of the test decryptor.

Percentage of encryption

Impersonation (enable or disable)

Encrypt shares (enable or disable)

Skip hidden folders (enable or disable)

Kill services (enable or disable)

The screenshots below demonstrate that the ransomware configuration provides options to either encrypt the entire corporate network or specific folders on the device. It also allows selecting a driver to terminate EDR/XDR processes (Rentdrv or Truesight).

As for the “original” version of the DragonForce ransomware, when an affiliate creates a builder, they set up a “client” page for the victim and can configure a DragonForce ransomware sample. They have the option to choose between the LockBit version or the original DragonForce sample, which is capable of terminating EDR/XDR processes.

With this version, affiliates can configure the following parameters:

Test decryption (enable or disable)

Time range for ransom payment and use of the test decryptor.

Encrypt whole system + Network or only Local Path

Percentage of encryption

Extension for encrypted files

Choice of driver to terminate EDR/XDR processes

After creating a new client, the affiliate can download samples related to the specific client. If a sample of the “original” DragonForce ransomware is selected, a set of samples for both Windows and ESXi will be downloaded.

The “original” version of the DragonForce ransomware offers greater customization options. It allows affiliates to encrypt either the entire system and corporate network or just specific local paths. Affiliates can also choose the file extension for encrypted files, select a driver to terminate EDR/XDR processes, and configure the name of the ransom note.

Within the “My Team” section contains an interface viewing advertisers (partners) related to the affiliate.

Figure 10. A screenshot of the “My Team” section.

The “Add Adver” section contains an interface for creating advertisers for the affiliate (adding partners), and editing access rights.

Figure 11. A screenshot of the “Add Adver” section.

The “Publications” section contains information data of victims that have been published on the dedicated leaks site by an affiliate of DragonForce.

Figure 12. A screenshot of the “Publications” section.

Within the “Constructor” section, affiliates can schedule a date for publishing victims’ data, in the event that the victims choose not to pay the ransom.

Figure 13. A screenshot of the “Constructor” section.

In the “Rules” section, the administrators of the DragonForce ransomware group publish their rules, guides, and contacts relating to the use of the DragonForce ransomware in Russian.

Figure 14. A screenshot of the “Rules” section.

Target Restrictions: Attacks on hospitals, critical infrastructure, non-profit organizations, CIS countries, and former USSR countries are prohibited.

Communication with Clients: Respectful communication is required with companies willing to cooperate.

Payment Procedure: The initial payment to the team is made to the affiliate program’s wallet. Subsequent payments are made to the team’s wallet. A deposit of 1 BTC may be required before the first payment.

Guarantor Responsibility: The guarantor is fully responsible for the invited partner and may be blocked for their violations.

Payment Distribution: The team receives 80% of the payment, and the affiliate program receives 20%. The partner must immediately pay the 20% amount.

Wallet Transfer for Payments: Carried out through the function in Actions, specifying the amount in BTC.

Timer Setup: Set when creating a Build. Standard: 14 days for access to Recovery, 7 days for payment negotiations.

Negotiation Rights: The DragonForce Ransomware affiliate program reserves the right to negotiate with the company in some cases (e.g., if the partner behaves inappropriately, disrespectfully, or fails to fulfill obligations).

File Upload Requirement: The partner must upload files from the attacked company to receive payment.

Ban on Political Influence: Any attempts at political influence are strictly prohibited.

Administrator/Team Leader Responsibility: Full responsibility for the team’s actions and ensuring that team members are familiar with the rules.

Discount Limitation: The maximum available discount is 45% of the specified decryption and file deletion purchase amount.

Ransom Amount Determination: The team independently determines the purchase amount, ranging from $100 to $1,000,000+.

Test Decryption: Operates in automatic mode, with support available in exceptional cases.

Team Trust Levels: Various trust levels, individually elevated, with corresponding privileges.

General Rule: Respect the rules of the affiliate program, clients, and administration.

Client: The target company attacked by the Alex Ransomware affiliate program.

Administrator/Team Leader: The responsible person overseeing the team.

Advertiser/Partner/Employee: A member of a specific team in the affiliate program.

Support: A support staff member in the affiliate program.

Affiliate Program Administrator: The head of the affiliate program administration.

Team: Partners of the Alex Ransomware program, a group of individuals responsible for attacks on companies.

Instructions for Using the Locker – DragonForce Windows Ransomware

DragonForce Ransomware (Windows)

A brief guide on using the DragonForce locker, an overview of locker functionality.

All: Combines Local and Network modes. Processes the local machine first, then network resources.

Local: Processes only the local machine, ignoring network resources.

Network: Works only with mounted network resources.

Path: Processes only the folders specified in the builder.

Test decryption: Automatic test decryption on the client page.

Encryption filename: Encrypts filenames.

Time sync: Synchronizes time in UTC format for correct operation of Scheduled job.

Scheduled job: Launches at the specified UTC time (HH:MM, e.g., 12:30).

Full encrypt threshold: Maximum file size in bytes for full encryption.

Header encrypt threshold: Maximum file size in bytes for encrypting only the header.

Header encrypt size: Header size in bytes for encryption.

Partial encryption: Ability to set file encryption percentage (from 20% to 80%).

Encrypted file extension: Extension for encrypted files (e.g., .pwnd).

Driver: Modes None/Rentdrv/Truesight for terminating processes.

Kill priority: List of processes for continuous termination.

Kill processes: List of processes for one-time termination.

Filenames (with extensions, e.g., readme.txt)

Team : Ability to the target with the team.

Advertisers chatting: Permission for team members to chat.

Advertisers timer managing: Permission for the team to manage the timer.

Advertisers locking: Permission for team members to lock the client.

Logs, splash screen, and icon are saved by default in C:\Users\Public\.

Logs are encrypted and can only be decrypted by the administrator.

The program must be run as an administrator to operate from SYSTEM.

The locker has been tested on most versions of Windows.

Figure 17. A screenshot of the “Contacts”.

Intruders : Tox – 1C054B722BCBF41A918EF3C485712742088F5C3E81B2FDD91ADEA6BA55F4A856D90A65E99D20

Within the “Blog” section contain links to the Dedicated Leaks Site (DLS) of DragonForce ransomware:

hxxp://z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid[.]onion

Figure 18. A screenshot of the “DLS” of the DragonForce ransomware.

The “Profile” section contains information the affiliate, their authentication history, as well as functions to change passwords, log out, and to check their unique onion page.

Figure 19. A screenshot of the “Profile” section of the DragonForce ransomware.

Tactics, Techniques, and Procedures (TTPs)

In 2023, Group-IB’s Digital Forensics and Incident Response (DFIR) team responded to an incident, and can now reveal the impact of the DragonForce ransomware by analyzing the attacker’s tactics, techniques, and procedures (TTPs) from initial access via a public facing web application server.

Incident Response Case: September DragonForce Attack

During the course of the investigation, Group-IB’s DFIR analysts identified the initial access to the target network through a public-facing remote desktop server. Suspicious login activity was observed involving three different IP addresses using valid domain accounts. These accounts were used to gain unauthorized access in September 2023.

Date and time of first sighting:

T1059.001 Command and Scripting Interpreter: PowerShell

Based on the data collected, Group-IB’s DFIR analysts found that PowerShell commands were executed on several hosts within the network. The purpose of these commands was to remotely download and execute a malicious payload, which was later identified as a Cobalt Strike beacon.

Figure 20: Snippet of the Remote Download of Cobalt Strike Beacon.

T1078.002 Valid Accounts: Domain Accounts

T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

T1543.003 Create or Modify System Process: Windows Service

They also identified compromised accounts that were used by the threat actor to maintain persistence, and move laterally within the organization. The SystemBC malware was found to create a registry key under “Software\Microsoft\Windows\CurrentVersion\Run” with the name “socks5” to ensure persistence. Two additional hosts were also found to be infected with SystemBC, although further data was unavailable for analysis.

Figure 21: Windows Defender event log quarantine of Cobalt Strike.

Figures 22 & 23: Attempted service installation on the system.

T1070.001 Indicator Removal: Clear Windows Event Logs

The ransomware executable “df.exe” was found to have the capability to clear Windows Event Logs after completing its encryption tasks. This action is likely intended to hinder forensic investigation post-attack.

Figure 24: Sample of logs cleared identified in the target network.

T1003.001 OS Credential Dumping: LSASS Memory

Group-IB’s DFIR analysts identified that the threat actor executed Mimikatz, a credential dumping tool, on four different hosts. The execution of Mimikatz resulted in the creation of a file named “123.txt,” which contained clear text credentials of the compromised users.

T1482 Domain Trust Discovery

T1018 Remote System Discovery

T1016 System Network Configuration Discovery

T1082 System Information Discovery

T1083 File and Directory Discovery

On one host, a compromised user executed the ADFind tool, saving the results in a file named “AD_subnet.txt.” This execution indicates that the attacker was gathering information the network’s Active Directory. Additionally, on two other hosts, the network scanner tool “netscanold.exe” was found to have been executed, further supporting the attacker’s efforts to map out the network.

T1021.001 Remote Services: Remote Desktop Protocol

Group-IB’s DFIR analysts determined that the attacker used Remote Desktop Protocol (RDP) to move laterally within the network. After gaining initial access through the public-facing web application server, the attacker used RDP to access internal servers and continued moving across the network.

Here’s a detailed list of the unique malicious activities observed during the RDP sessions:

Multiple RDP Connections – Used for lateral movement within the network.

Mimikatz Execution – Used to dump credentials from LSASS memory.

ADFind Execution – Used for Active Directory enumeration.

SystemBC, CobaltStrike, and Network Scanner Execution – Used to establish persistence, command-and-control communication, and perform network reconnaissance.

Disabling Antivirus – Antivirus features were disabled, exceptions added, and antivirus uninstalled to avoid detection.

Ransomware Execution – Deployed ransomware to encrypt files across multiple systems.

Clearing Event Logs – Event logs were cleared after ransomware execution to cover tracks.

T1071.001 Application Layer Protocol: Web Protocols

Analysis of the Cobalt Strike beacons revealed the command-and-control (C2) address 185[.]73[.]125[.]8 utilizing the HTTP protocol. An additional C2 address associated with SystemBC malware was identified as 94[.]232[.]46[.]202. Firewall logs indicated connections to these C2 addresses.

T1486 Data Encrypted for Impact

Ransomware was deployed across the network, with the malicious executable responsible for the encryption identified as “ df.exe ”.

Figure 25: Screenshot of the ransom note.

The file socks.exe with corresponding MD5-hash checksum 97B70E89B5313612A9E7A339EE82AB67 is a backdoor which allows a remote attacker to upload additional executable files and execute them on a controlled host, which is related to a malware family “SystemBC”.

The file socks.exe is configured to connect to a C2 server with the IP-address 94[.]232.46.202 every 180 seconds. Upon the attacker’s command, the sample can download the file, save it in a specified directory on the infected host and execute it.

The file socks.exe can also achieve persistence by creating a value with a name “ socks5 ” within the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Run , which is responsible for automatic execution upon user logon or system boot. When the user logs on or initiates a system boot, the created value will contain the command ‘powershell.exe -windowstyle hidden -Command & ‘path_to_executable_file’, which will be executed, where ‘path_to_executable_file’ is a file path where a SystemBC sample is located in a filesystem.

The file a65.exe with corresponding MD5-hash checksum A50637F5F7A3E462135C0AE7C7AF0D91 is a payload of the post-exploitation framework Cobalt Strike which allows remote attacker to perform various actions on an infected system, including but not limited to, uploading/downloading files, executing files and commands in command interpreter, gather credentials of users, move laterally across network. The file is configured to connect to a URL http[:]//185[.]73.125.8/ broadcast and receive commands from this URL.

The file netscanold.exe with corresponding MD5-hash checksum BB7C575E798FF5243B5014777253635D is a network scanning tool known as SoftPerfect Network Scanner. It is a system administration tool which allows its user to get the list of reachable hosts and network shares, as well as perform connection to discovered hosts via RDP, WMI, SMB.

The file df.exe with corresponding MD5-hash checksum C111476F7B394776B515249ECB6B20E6 is a malicious file which is intended to encrypt contents of files within the filesystem. It utilizes a combination of RSA-1024 and Salsa20 encryption algorithms, so it is impossible to decrypt files without the knowledge of a private key. After the encryption of files is completed, df.exe clears the Windows event logs.

In the section, we turn our attention to the different versions of the DragonForce ransomware.

Technical information ransomware builds

DragonForce offers two different builds. Based on the information they provided, one is a variant of LockBit 3.0, while the other was claimed by DragonForce to be their own original Dragonforce ransomware variant. However, after analysis of the latter, we found that it is actually a variant of ContiV3, enhanced with new features such as the “Bring Your Own Vulnerable Driver” (BYOVD).

This is unsurprising as modern ransomware operators are increasingly reusing and modifying builders from well known ransomware families that were leaked, to tailor to their needs. Conti, Babuk, LockBit are among the common families that have been modified.

A sample of this has been seen in the wild since July 2024. It creates a mutex “dragonforce_encrypted_system” and usually renames files with a “.dragonforce_encrypted” extension, which can be changed by its affiliates. As ContiV3 codes have been leaked and analyzed, we will mainly focus on features that have been added by DragonForce.

New features! Buy me instead! (Differences from Conti)

Embedded Configuration

Bring Your Own Vulnerable Driver (BYOVD) for process termination

Persistence via Scheduled tasks

DragonForce wallpaper and icon

Obfuscation / Anti-analysis

Its anti-analysis techniques are inherited from Conti.

String obfuscation using ADVobfuscator

Resolving APIs by Hash – Names are hashed with `MurmurHash2A` algorithm with the seed value of `0xB801FCDA`

Anti-hooking – compares the currently loaded functions with the original files. If the bytes have been modified, it replaces them with the original bytes

Deleting Shadow Copy with COM Objects – enumerates shadow copies and deletes them.

Command-line Arguments

These are mostly inherited from Conti as well.

In contrast to Conti, DragonForce embeds a configuration inside the binary so that no command line options are needed. However, when command line options are used, it will override those specified in the configuration.

Figure 26: Screenshot of a snippet of decrypted configuration.

These configuration values correspond to the aforementioned guides. Here’s a concise summary, to spare one from reading the nitty-gritty byte-by-byte details:

BYOVD for terminating processes

Conti uses Windows Restart Manager to kill processes that are currently using the resources. DragonForce has implemented additional ways to kill processes, especially for protected processes.

The “Bring Your Own Vulnerable Driver” (BYOVD) technique has become a favored technique within ransomware groups to disable EDR products. This tactic involves bringing vulnerable drivers onto compromised systems and leveraging them to execute malicious code at the kernel level. By default, 64-bit versions of Windows Vista and later will load a kernel-mode driver only if the kernel can verify the driver signature. DragonForce abuses digitally signed but vulnerable drivers by bringing them onto the systems and using it to terminate critical AV or EDR processes, enabling them to operate undetected in the compromised environment.

During the build phase, two different vulnerable driver options are provided to the user. These drivers expose IOCTL commands with privileged functionality, but lack adequate access controls. The selected driver is then compressed, encrypted, and then embedded into the binary. Both drivers perform the same method of process termination by calling `ZwOpenProcess()` and `ZwTerminateProcess()`. Both drivers have been published on the Microsoft recommended driver block rules .

TrueSight.sys is actually a RogueKiller Antirootkit Driver v3.3 developed by Adlice Software. The company, Adlice, has already published a fix in v3.4. The `0x22E044` control code terminates the target process provided by its PID.

Figure 27: Screenshot of the `0x22E044` control code in Truesight driver.

A driver developed by Hangzhou Shunwang Technology. Not much information the driver can be found online. The `0x220E010` control code terminates the target process provided by its PID.

Figure 28: Screenshot of the `0x220E010` control code in RentDrv driver.

In user-mode, the program retrieves a device handle to the driver and communicates with the driver via DeviceIoControl. Since the methods of loading and using these drivers are similar, codes are reused and supplement with a simple switch statement.

Figure 29: Screenshot of the program communicating with the driver via DeviceIoControl.

Although DragonForce has advertised that one can configure two kill processes lists– one for a single termination and the other for continuous termination–we found that it starts two threads for killing processes. Both threads actually run in an infinite loop constantly checking for processes to be terminated. The ‘priority’ thread sleeps for 15 ms after checking, while the ‘normal’ thread sleeps for 250 ms per loop.

In order to kill processes, the ransomware requires at least administrator privileges. Once it confirms that it has elevated privileges, it attempts to execute itself as SYSTEM using Access Token Manipulation.

It enumerates running processes to find one running with SYSTEM-level privileges, then duplicates its access token with `DuplicateTokenEx()`, and uses it with `CreateProcessWithTokenW()` to create a new process running under the security context of `NT AUTHORITY\SYSTEM`.

Figure 30: Screenshot of the program attempting to perform privilege escalation.

There are no major modifications to Conti’s encryption schema, except that some values are now customizable during the build and filenames can be encrypted.

For those that are unfamiliar with Conti’s encryption schema, for each file, the ChaCha8 key and IV is generated by the `CryptGenRandom()` function. They are then used to initialize the ChaCha8 initial state and subsequently to encrypt the file. The key and IV are then concatenated, encrypted with RSA and appended to the end of the file.

Other than the four encryption modes (all, net, local, path) mentioned in the above operator guide, there are three different encryption types, namely, FULL_ENCRYPT, PARTLY_ENCRYPT, HEADER_ENCRYPT and the type of encryption is chosen based on their file types and file sizes:

Files with Database extensions are fully encrypted

Files with Virtual machine extensions are 20% encrypted

For other files: File size < full_encrypt_threshold: Full encryption File size < header_encrypt_threshold: Only the first [header_encrypt_size] bytes are encrypted Other: Encrypted by [other_encrypt_chunk_percent]

File size < full_encrypt_threshold: Full encryption

File size < header_encrypt_threshold: Only the first [header_encrypt_size] bytes are encrypted

Other: Encrypted by [other_encrypt_chunk_percent]

The following is a list of database file extensions:

The following is a list of virtual machine file extensions:

For Network Encryption, it enumerates network shares and encrypts shares that are not named “ADMIN$”.

When the encrypt_filename option is checked, filenames are encoded with Base32 with the following custom set of alphabet `gwfn6l3bk45o2zecvi7xtyqrpsudmahj`

Persistence via Scheduled tasks

This DragonForce variant of Conti ransomware has the option to create scheduled tasks. It uses the COM TaskScheduler class to schedule a task daily to run the current binary, specifying a time and task name. They can also choose to move the binary to a different location and run the scheduled task from there instead. COM objects allow privileged users to schedule a task without using the `schtasks` or the `at` command.

Dragonforce has more verbose logging, of course only if the logging option is turned on. It logs the selected configuration values and also the encryption type (i.e. if it is excluded, full, header, or percentage) used per file. Each line of log is preceded with the execution time and thread ID. Logs are encrypted with ChaCha8 and written to C:\Users\Public\log.log

Here are some snippets of decrypted logs:

Figure 31: Screenshot of the configuration values in decrypted logs.

Figure 32: Screenshot of file encryption process in decrypted logs.

Wallpaper, Icon and Ransom note

Figure 33: Screenshot of the wallpaper and icon of DragonForce after a system has been encrypted.

Figure 34: Screenshot of the ransom note.

LockBit 3.0 is also known as LockBit Black ransomware. It gained this alias as LockBit 3.0 seems to reuse code from BlackMatter ransomware.

The sample that we have obtained does not require a custom password to execute, as most LockBit 3.0 samples are observed to have been generated using the password option. There were very little differences observed between this and other generic LockBit 3.0 variants , hence we will not go into details here.

Comparing the customisation options currently provided in the builder and the JSON configuration used in LockBit 3.0, it was only a subset of what LockBit 3.0 offered. As LockBit 3.0 uses a separate JSON file for build configuration, it is rather easy for DragonForce to expand the configuration options offered in their builder in the future as well.

The following is a sample of the JSON configuration for Lockbit:

The DragonForce ransomware group has rapidly emerged as one of the most dangerous threats in the cybersecurity domain, largely due to their use of two distinct ransomware variants: a fork of LockBit, and a highly customized fork of Conti. The Conti variant offers significant advantages, including advanced encryption techniques, the ability to terminate EDR/XDR processes using the “Bring Your Own Vulnerable Driver” (BYOVD) method, and enhanced anti-analysis features. These enhancements make their attacks more sophisticated and difficult to detect and mitigate.

Additionally, the integration of SystemBC malware into their operations add another layer of complexity. SystemBC facilitates persistent access, enables network reconnaissance, and supports lateral movement within compromised networks, making it a critical component of their attack chain.

How to prevent ransomware? Although ransomware groups have gained notoriety for targeting companies in critical sectors, they are a threat to organizations across all industries. In addition to having new members in its network, ransomware affiliate programs equip members with upgraded tools and techniques. That being said, it is essential that businesses take specific steps immediately to keep their mission-critical operations and data secure. We recommend the following:

Add more layers of security: Multi-factor authentication (MFA) and credential-based access solutions help businesses secure their critical assets and high-risk users, making it harder for attackers to be successful.

Stop ransomware with early detection: Leverage the behavioral detection capabilities of the Endpoint Detection and Response (EDR) solution to help identify ransomware indicators across your managed endpoints, promptly alerting your teams to any suspicious activity for further scrutiny. This proactive approach enables agile detection, investigation and remediation of both known and unknown threats on your endpoints.

Have a backup strategy: Data backup processes should be conducted regularly as they reduce damage and help organizations avoid data loss following ransomware attacks.

Leverage an advanced malware detonation solution: Organizations should leverage AI-infused, advanced analytics-based solutions to detect intrusions in real time. Learn how Group-IB’s Managed XDR coupled with Threat Intelligence helps businesses to: gain insights into the unique Tactics, Techniques, and Procedures (TTPs) used by Advanced Persistent Threats (APTs) and other cybercriminal groups and pivot their security strategies accordingly; and enable multi-layered cybersecurity (endpoint, email, web, and network) through automated threat detection and response.

gain insights into the unique Tactics, Techniques, and Procedures (TTPs) used by Advanced Persistent Threats (APTs) and other cybercriminal groups and pivot their security strategies accordingly; and

enable multi-layered cybersecurity (endpoint, email, web, and network) through automated threat detection and response.

Patch it up: The longer a vulnerability remains unpatched, the greater the risk that it will be exploited by cybercriminals. Security patches should therefore be prioritized, and organizations should also set up a process to regularly review and apply patches as they become available.

Train employees: The human factor remains one of the greatest vulnerabilities in cybersecurity. Educate employees the risks relating to the organization’s network, assets, devices, and infrastructure. Organizations should conduct training programs and security drills to help employees identify and report the tell-tale signs of cybercrime (e.g. phishing emails).

Control vulnerabilities: Do not turn a blind eye to emerging vulnerabilities. Checking your infrastructure annually with a technical audit or security assessment is not only a good habit, it also adds a much-needed layer of protection. Infrastructural integrity and digital hygiene processes should be monitored continually.

Financially-motivated threat actors are driven to make you pay more. Even if one attacker returns your data, another will find out your willingness to pay, which will lead to an increase in the number of attempted attacks on your company. The best you can do is to incident response experts as quickly as possible.