Executive Summary
DragonForce is a Ransomware-as-a-Service (RaaS) ecosystem that emerged in late 2023, gaining significant traction in 2025 and 2026. The group has been linked to disruptive attacks against UK retail sectors and is frequently deployed by affiliates such as Octo Tempest. While the ecosystem supports a wide range of intrusion activities, the core Windows locker is a specialized impact tool designed for high-speed encryption of local and network-accessible data.
The technical analysis reveals a network-aware but non-wormable locker. It utilizes ChaCha8 for file encryption and RSA-4096 for recovery material protection, featuring specialized modes for handling large database and virtual machine files. The locker is capable of terminating 38 specific processes and inhibiting recovery by deleting shadow copies via WMI/WMIC.
DragonForce represents a significant threat to manufacturing, professional services, and technology sectors due to its ability to damage large-scale assets quickly. Although it lacks autonomous propagation and exfiltration code, its ability to enumerate and encrypt all writable SMB shares under a compromised security token allows a single infected host to cause widespread operational downtime.
