SYMBOLCOMMON_NAMEaka. SYNONYMS
win.dragonforce (Back to overview)

DragonForce

VTCollection    

According to Idan Malihi, this ransomware is based on the LockBit builder from 2022, utilizing similar configurations and attack methods. The ransomware’s icon and wallpaper are embedded in the binary’s overlay, compressed with Zlib, and loaded dynamically during execution.

References
2026-02-03 ⋅ LevelBlue ⋅ Evgeny Ananin, Mark Tsipershtein
The Godfather of Ransomware? Inside DragonForce’s Cartel Ambitions
DragonForce
2026-01-14 ⋅ S2W Inc. ⋅ Byeongyeol An
Detailed Analysis of DragonForce Ransomware
DragonForce
2025-05-06 ⋅ Mandiant ⋅ Mandiant
Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines
BlackCat DragonForce RansomHub
2025-05-06 ⋅ Mandiant ⋅ Mandiant
Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines
BlackCat DragonForce RansomHub
2025-03-11 ⋅ Idan Malihi ⋅ Idan Malihi, Yaniv Azran
DragonForce Ransomware: Unveiling Its Tactics and Impact
DragonForce
Yara Rules
[TLP:WHITE] win_dragonforce_auto (20260917 | Detects win.dragonforce.)
rule win_dragonforce_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.dragonforce."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dragonforce"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 83ec18 8d8c24ec050000 8bd4 8d7102 }
            // n = 4, score = 100
            //   83ec18               | sub                 esp, 0x18
            //   8d8c24ec050000       | lea                 ecx, [esp + 0x5ec]
            //   8bd4                 | mov                 edx, esp
            //   8d7102               | lea                 esi, [ecx + 2]

        $sequence_1 = { c645a015 c645a136 c645a215 c645a339 }
            // n = 4, score = 100
            //   c645a015             | mov                 byte ptr [ebp - 0x60], 0x15
            //   c645a136             | mov                 byte ptr [ebp - 0x5f], 0x36
            //   c645a215             | mov                 byte ptr [ebp - 0x5e], 0x15
            //   c645a339             | mov                 byte ptr [ebp - 0x5d], 0x39

        $sequence_2 = { c645d516 c645d66c c645d715 c645d86c }
            // n = 4, score = 100
            //   c645d516             | mov                 byte ptr [ebp - 0x2b], 0x16
            //   c645d66c             | mov                 byte ptr [ebp - 0x2a], 0x6c
            //   c645d715             | mov                 byte ptr [ebp - 0x29], 0x15
            //   c645d86c             | mov                 byte ptr [ebp - 0x28], 0x6c

        $sequence_3 = { 8b3d???????? 8bb4249c000000 33c0 668984244c050000 }
            // n = 4, score = 100
            //   8b3d????????         |                     
            //   8bb4249c000000       | mov                 esi, dword ptr [esp + 0x9c]
            //   33c0                 | xor                 eax, eax
            //   668984244c050000     | mov                 word ptr [esp + 0x54c], ax

        $sequence_4 = { 6a01 13c0 f7d8 6a00 }
            // n = 4, score = 100
            //   6a01                 | push                1
            //   13c0                 | adc                 eax, eax
            //   f7d8                 | neg                 eax
            //   6a00                 | push                0

        $sequence_5 = { 8d8424c0050000 8bcc 50 e8???????? }
            // n = 4, score = 100
            //   8d8424c0050000       | lea                 eax, [esp + 0x5c0]
            //   8bcc                 | mov                 ecx, esp
            //   50                   | push                eax
            //   e8????????           |                     

        $sequence_6 = { 8b0485f0524600 80640828fe ff33 e8???????? }
            // n = 4, score = 100
            //   8b0485f0524600       | mov                 eax, dword ptr [eax*4 + 0x4652f0]
            //   80640828fe           | and                 byte ptr [eax + ecx + 0x28], 0xfe
            //   ff33                 | push                dword ptr [ebx]
            //   e8????????           |                     

        $sequence_7 = { 0f477d08 c645e000 c645e144 c645e22c }
            // n = 4, score = 100
            //   0f477d08             | cmova               edi, dword ptr [ebp + 8]
            //   c645e000             | mov                 byte ptr [ebp - 0x20], 0
            //   c645e144             | mov                 byte ptr [ebp - 0x1f], 0x44
            //   c645e22c             | mov                 byte ptr [ebp - 0x1e], 0x2c

    condition:
        7 of them and filesize < 879616
}
Download all Yara Rules