• Products & Services
        • Cloud

          • Endpoint Protection
          • Endpoint Detection and Response
          • Mobile Device Management
          • BYOD
          • Extended Detection and Response
          • Zero Trust Network Access
          • Data Privacy
        • On Prem

          • Endpoint Protection
          • Endpoint Detection and Response
          • Data Privacy
        • Platform

          • Malware Analysis Platform
        • Small Business

          • SOHO Total Edition
        • Services

          • Threat Intel
          • Digital Risk Protection Services (DRPS)
          • Ransomware Recovery as a Services (RRaaS)
          • DPDP Compliance
          • Managed Detection and Response
          • Cybersecurity & Data Privacy Awareness
  • Solutions
    • BFSI
    • Education
    • Government
    • Healthcare
    • ITeS
    • Manufacturing
  • Company
    • About Seqrite
    • Leadership
    • Awards & Certifications
    • Newsroom
  • Partners
    • Partner Program
    • Locate Partner
    • Become A Partner
  • Support
  • Resources
    • Blogs
    • Whitepapers
    • Datasheets
    • Case Studies
    • Threat Reports
    • Manuals
    • PoV
    • Understanding Data Privacy
    • Check You Risk Score
    • DPDP Dialogues
    • Privacy Hour
Seqrite Labs Blog
Contact Sales Under Attack?
  • Products & Services
        • Cloud

          • Endpoint Protection
          • Endpoint Detection and Response
          • Mobile Device Management
          • BYOD
          • Extended Detection and Response
          • Zero Trust Network Access
          • Data Privacy
        • On Prem

          • Endpoint Protection
          • Endpoint Detection and Response
          • Data Privacy
        • Platform

          • Malware Analysis Platform
        • Small Business

          • SOHO Total Edition
        • Services

          • Threat Intel
          • Digital Risk Protection Services (DRPS)
          • Ransomware Recovery as a Services (RRaaS)
          • DPDP Compliance
          • Managed Detection and Response
          • Cybersecurity & Data Privacy Awareness
  • Solutions
    • BFSI
    • Education
    • Government
    • Healthcare
    • ITeS
    • Manufacturing
  • Company
    • About Seqrite
    • Leadership
    • Awards & Certifications
    • Newsroom
  • Partners
    • Partner Program
    • Locate Partner
    • Become A Partner
  • Support
  • Resources
    • Blogs
    • Whitepapers
    • Datasheets
    • Case Studies
    • Threat Reports
    • Manuals
    • PoV
    • Understanding Data Privacy
    • Check You Risk Score
    • DPDP Dialogues
    • Privacy Hour
Home  /  Technical  /  Inside DragonForce: How a Ransomware Cartel’s Payload Actually Runs
Inside DragonForce: How a Ransomware Cartel’s Payload Actually Runs
01 October 2026

Inside DragonForce: How a Ransomware Cartel’s Payload Actually Runs

Written by Ayush Singh Sachan
Ayush Singh Sachan
Technical

A technical walkthrough from runtime preparation and network-share discovery to concurrent file encryption

DragonForce is a Ransomware-as-a-Service (RaaS) operation that first surfaced in mid-to-late 2023. It initially presented itself as a hacktivist collective before shifting to a profit-driven model. Early payloads were built on leaked LockBit 3.0 source code and later supplemented with code derived from the leaked Conti builder. In March 2025, the operation restructured into a “ransomware cartel” model, offering white-label infrastructure that allows affiliates to operate under their own branding while relying on DragonForce’s backend tooling. By mid-2026, its leak site had claimed several hundred victims across dozens of countries.

We traced a Windows DragonForce sample from process entry through the final return from its main routine. The observed execution combines runtime preparation, process interference, shadow-copy deletion, ARP-based SMB target discovery, parallel file encryption, and desktop customization.

Execution flow at a glance

The diagram separates the main-thread progression from activity that runs in the background. Target discovery publishes local and network paths to distinct queues, which the encryption workers consume as tasks become available.

Figure 1. Execution flow of the analyzed sample. Dashed connectors indicate background process monitoring

Runtime preparation and host reconnaissance

Process startup and API resolution

Two TLS callbacks perform compiler-generated runtime setup before the PE entry point passes execution to the C Runtime (CRT). The CRT then calls DragonForce_Main(), where the sample begins its own initialization.

DragonForce manually resolves LoadLibraryA from kernel32.dll, then uses it to load eleven Windows libraries using decrypted DLL names. GetProcAddress() resolves the required functions from those modules. The resolver inspects returned stubs for relative or indirect jumps and checks that the jump targets fall within the sample’s .idata section, validating the expected import-table thunks. The resolved APIs are already represented in the PE import table, so this mechanism does not conceal those capabilities from static import inspection. If the initial LoadLibraryA resolution fails, the sample exits before continuing.

Encoded strings

File paths, registry paths, DLL names, API names, process names, command-line switches, and other meaningful strings are stored in encoded form and recovered when needed. The same routine is reused throughout execution. It applies a reversible affine transform modulo 127, with multiplication by 7 during encoding and the modular inverse during decoding. This keeps strings out of their directly usable form in the binary, while the decoded values become available in memory when required.

Encoding: E(x) = (7x + 0x6A) mod 127
Decoding: D(y) = (109 * (y – 0x6A)) mod 127

Configuration and encrypted logging

The embedded configuration is stored as one encrypted blob. At startup, the sample constructs a ChaCha20 state, decrypts the blob, and splits the resulting pipe-delimited string into individual settings. The recovered configuration-decryption state was identical in the two observed executions.

The runtime log is written to C:\Users\Public\log.log. Its first 16 bytes contain the build_key and instance_key in plaintext, eight bytes each. Subsequent entries include a timestamp and thread identifier, are encrypted with a separate ChaCha20 state, and are written to the same file. The entries record host identity, elevation, process handling, drive discovery, share processing, and file activity. The log is a useful execution artifact when the relevant key material is available.

Host reconnaissance

Before target processing, the sample retrieves the current user SID and resolves account information, checks token elevation, obtains its executable path, and checks whether it is running under WOW64. The analyzed sample was a 32-bit executable running on 64-bit Windows, and its runtime log recorded an elevated process token.

Process interference and recovery preparation

A configurable priority list contains 38 process names spanning security, backup, database, and productivity software. Background monitoring workers repeatedly enumerate running processes, compare names against this list, and attempt to terminate matches. In the observed runs, opening MsMpEng.exe failed with ERROR_ACCESS_DENIED, while Firefox.exe was successfully terminated.

DragonForce also initializes COM and WMI, queries the Win32_ShadowCopy class, and uses each returned shadow-copy identifier to construct and execute a WMIC deletion command. This removes the local Volume Shadow Copies before file processing begins:

cmd.exe /c C:\Windows\System32\wbem\WMIC.exe shadowcopy where “ID='<shadow-copy-id>'” delete

When a target file cannot initially be opened, a separate path invokes the Windows Restart Manager. In the documented example, opening C:\DumpStack.log.tmp returned ERROR_SHARING_VIOLATION, and the file was skipped.

Discovering local and network targets

The sample enumerates logical drives with GetLogicalDriveStringsW(). The observed run identified C:\ and D:\ and published them to the local-drive task queue. Local-drive discovery and file processing overlap: workers begin on a published drive before enumeration of the remaining drive has finished.

For network discovery, DragonForce reads the existing IPv4 ARP cache through GetIpNetTable() and filters candidate addresses against embedded prefixes. This uses hosts already represented in the cache rather than actively scanning the subnet. For each candidate address, NetShareEnum() enumerates SMB shares and the reachable paths are published to the network task queue.

The recovered runtime log records seventeen share discoveries across more than a dozen internal addresses. Most were administrative C$ shares, but non-C$ shares such as \\192.168.9.114\share and \\192.168.9.114\Users also reached the task-publication path. The sample then processed files through multiple SMB shares alongside local-drive targets.

Concurrent file encryption

DragonForce creates sixteen encryption workers in two batches of eight. One batch consumes tasks from the local-drive queue, while the other consumes tasks from the network-share queue. Each batch uses its own synchronized task structure. Workers can therefore process local and network targets concurrently as discovery publishes new paths.

Per-file key handling

For each file, the sample generates fresh material with CryptGenRandom(): a 32-byte key and an 8-byte state value. These values initialize a new ChaCha20 state used to encrypt the file content. The per-file material is then protected with CryptEncrypt() using the RSA public key embedded in the sample. The 0x214-byte PUBLICKEYBLOB carries the RSA1 marker and contains a 4096-bit modulus with public exponent 65537.

After encryption, the sample appends two distinct records to the file and finalizes it with SetEndOfFile():

WriteFile: 0x20C bytes (524-byte RSA-processed record)
WriteFile: 0x0D bytes (13-byte metadata footer)
SetEndOfFile()

The 13-byte footer stores the encryption-percentage flag and the original file size. The observed full-encryption example uses a percentage value of 100. The RSA private key is not embedded in the analyzed sample.

File filtering and renaming

Before processing, workers apply directory, extension, and filename exclusions, including the configured readme.txt exclusion. The sample also checks the DLOGFILE0001 content marker and skips a file when it is present. A separate hardcoded list of more than 200 database and virtualization-related extensions routes matching files to the 20% partial-encryption path. The observed Victim.txt example followed the full-encryption path.

Recovered setting Configured value
full_encrypt_threshold 2,097,152 bytes (2 MB)
header_encrypt_threshold 10,485,760 bytes (10 MB)
header_encrypt_size 3,145,728 bytes (3 MB)
other_encrypt_chunk_percent 20%

Once encryption is complete, the original filename is replaced with a randomized alphabetic name and the configured .df_win extension. The observed example changed Victim.txt to 5stq3an4ztrbkhnt.df_win.

Ransom note and cartel branding

Before encrypting files in a directory, DragonForce writes a readme.txt ransom note. The note identifies the operation as “The DragonForce Ransomware Cartel” and claims that data was stolen before encryption, offering to provide a list of the stolen files. Its build/instance key-derived identifier can be correlated with the runtime artifacts from the same sample.

The analyzed execution did not show a data-upload operation or a separate exfiltration channel. The ransom note’s data-theft statement is therefore a claim made by the note, not a behavior demonstrated in the execution trace.

Desktop customization and completion

After worker cleanup, the sample extracts an icon and wallpaper embedded in its executable and writes them to C:\Users\Public\icon.ico and C:\Users\Public\wallpaper_white.png. It creates the HKEY_CLASSES_ROOT\.df_win\DefaultIcon association so Windows can display the custom icon for encrypted files.

Figure 2. The file-type icon association created for the .df_win extension.

The wallpaper routine enumerates HKEY_USERS and attempts wallpaper-related registry writes for the listed profile contexts, then calls SystemParametersInfoW() to apply the wallpaper to the active session.

Figure 3. Wallpaper image extracted from the sample and applied to the active session.

The sample records a final Finish entry, flushes and closes its runtime log, frees remaining memory, and returns from DragonForce_Main() through the normal CRT shutdown path.

Execution perspective

The analyzed sample combines early process interference and recovery-point deletion with ARP-based network discovery and a parallel encryption engine that treats local drives and SMB shares as separate work streams. Per-file ChaCha20 encryption, RSA-protected key material, appended metadata, randomized .df_win names, and desktop changes complete the observed execution chain.

For the complete execution trace, MITRE ATT&CK mapping, indicators of compromise, and function/address reference, see the full technical analysis:

Read the full technical Whitepaper

 Previous PostThe Breach that Never Touches your Network
Ayush Singh Sachan

About Ayush Singh Sachan

Security Researcher specializing in malware analysis, Windows internals, and kernel debugging. At Quick Heal Technologies, I analyze PE, DLL, and driver-based...

Articles by Ayush Singh Sachan »

Related Posts

  • MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures

    September 8, 2026
  • Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor

    August 17, 2026
  • Abusing Trusted Business Workflows: A Multi-Stage Phantom Stealer Campaign

    July 22, 2026
Featured Authors
  • Seqrite
    Seqrite

    Seqrite is a leading enterprise cybersecurity solutions provider. With a focus...

    Read more articles by Seqrite
  • Bineesh P
    Bineesh P

    I am a passionate cybersecurity enthusiast and a dedicated writer. With a knack...

    Read more articles by Bineesh P
  • Jyoti Karlekar
    Jyoti Karlekar

    I'm an avid writer who enjoys crafting content about emerging technologies and...

    Read more articles by Jyoti Karlekar
  • Sanjay Katkar
    Sanjay Katkar

    Sanjay Katkar is the Joint Managing Director of Quick Heal Technologies...

    Read more articles by Sanjay Katkar
Topics
apt (25) Cyber-attack (36) cyber-attacks (58) cyberattack (16) cyberattacks (15) Cybersecurity (343) cyber security (34) Cyber threat (33) cyber threats (51) data breach (56) data breaches (29) data loss (28) data loss prevention (34) data privacy (17) data protection (35) data security (19) DLP (50) DPDP (14) DPDPA (17) Encryption (16) endpoint security (113) Enterprise security (20) Exploit (13) GDPR (14) malware (76) malware analysis (15) malware attack (23) MDM (27) Microsoft (15) MITRE ATT&CK (14) Network security (26) phishing (30) Ransomware (69) ransomware attack (31) ransomware attacks (31) ransomware protection (17) Seqrite (41) Seqrite Encryption (27) Seqrite EPS (33) Seqrite Services (16) threat detection (15) Threat Intelligence (24) UTM (34) Vulnerability (16) zero trust (13)
Seqrite Labs

Leading enterprise IT security solutions provider simplifying endpoint, data, and network security with best-in-class threat prevention, detection, and response solutions worldwide.

Read More About Seqrite

Follow us:

Subscribe To Our Newsletter

Stay informed about the latest cybersecurity trends and insights.

Loading
Products & Services
  • Cloud
  • Endpoint Protection
  • Endpoint Detection and Response
  • Mobile Device Management
  • BYOD
  • Extended Detection and Response
  • Zero Trust Network Access
  • Data Privacy
  • On Prem
  • Endpoint Protection
  • Endpoint Detection and Response
  • Data Privacy
  • Platform
  • Malware Analysis Platform
  • Micro Business
  • SOHO Total Edition
  • Services
  • Threat Intel
  • Digital Risk Protection Services (DRPS)
  • Ransomware Recovery as a Services (RRaaS)
  • DPDP Compliance
  • Managed Detection and Response
  • Cybersecurity & Data Privacy Awareness
Resources
  • Blogs
  • Whitepapers
  • Datasheets
  • Threat Reports
  • Manuals
  • PoV
  • Understanding Data Privacy
  • DPDP Dialogues
  • Policy & Compliance
  • EULA
  • GoDeep.AI
  • SIA
  • Privacy Hour
Contact Us
  • Registered Offices
  • Let’s Talk Cybersecurity
Support
  • Technical Support
  • Download Software
  • Offline Updater
  • Firmware Upgrades
  • Upgrades
  • Product Documentation
About Us
  • About Seqrite
  • Leadership
  • Awards & Recognition
  • Newsroom
Partner
  • Partner Program
  • Locate Partner
  • Become A Partner
  • Seqrite Certification

© 2026 Quick Heal Technologies Ltd.

Sitemap Privacy Policies Legal Notices Cookie Policies Terms Of Use