DragonForce Ransomware: Technical Analysis of Its Attack Methods
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
DragonForce is a Ransomware-as-a-Service (RaaS) operation that has evolved from a hacktivist collective into a financially motivated cartel. The malware employs advanced techniques including ChaCha20 encryption, RSA-4096 key protection, and ARP-based network discovery to propagate across local and network drives. It also targets security and backup-related processes to maximize the impact of file encryption.
Investigation
The investigation included an in-depth technical analysis of a Windows DragonForce sample, following execution from the initial process entry through its primary routine. Analysts examined runtime initialization, API resolution methods, encoded string handling, and the malware’s multi-threaded encryption engine. The research also documented techniques used for shadow-copy deletion and desktop customization.
Mitigation
To mitigate DragonForce, organizations should enforce strict access controls on administrative SMB shares and monitor for unauthorized WMIC activity used to delete shadow copies. Preventing unauthorized process termination and maintaining offline, immutable backups are essential defensive measures. Security teams should also monitor unusual ARP cache activity and rapid file-renaming behavior as potential early detection indicators.
Response
When DragonForce activity is detected, immediately isolate affected hosts from the network to stop lateral movement through SMB. Terminate suspicious processes and investigate unauthorized changes to registry keys or wallpaper settings. Perform a comprehensive forensic analysis of the C:\Users\Public\log.log file, where available, to help reconstruct the attack timeline and related encryption activity.
Attack Flow
We are still updating this part.
Detections
Create or Delete Shadow Copy via Powershell, CMD or WMI (via cmdline)
Suspicious Files in Public User Profile (via file_event)
DragonForce Ransomware Encrypted Log Files and Extension Rename [Windows File Event]
DragonForce Ransomware – Process Interference and Shadow Copy Deletion [Windows Process Creation]
Simulation Execution
-
Attack Narrative & Commands: The adversary initiates a high-pressure ransomware deployment. To prevent the system from recovering after the payload executes, the attacker first attempts to disrupt the local security environment by targeting
MsMpEng.exe(Windows Defender) usingtaskkill. Following this, the attacker executes a command viawmic.exeto delete Volume Shadow Copies, ensuring that the user cannot simply “roll back” the system to a previous state. Finally, to ensure a clean execution environment and clear traces of certain tools, the attacker usestaskkill /Fto forcefully terminate running processes. -
Regression Test Script:
# DragonForce Ransomware Simulation Script # This script simulates the specific TTPs defined in the detection rule. Write-Host "[!] Starting DragonForce Simulation..." -ForegroundColor Red # 1. Simulate Security Interference (Attempting to kill Defender) # Note: This will likely fail due to lack of SYSTEM permissions, # but the command execution itself will trigger the detection. Write-Host "[*] Simulating security interference via taskkill..." Start-Process "taskkill.exe" -ArgumentList "/IM MsMpEng.exe" -WindowStyle Hidden # 2. Simulate Shadow Copy Deletion via WMIC Write-Host "[*] Simulating Shadow Copy deletion via WMIC..." Start-Process "wmic.exe" -ArgumentList "shadowcopy delete" -WindowStyle Hidden # 3. Simulate Forceful Application Termination # We use notepad.exe as a target for the force flag simulation. Write-Host "[*] Simulating forceful application termination..." Start-Process "notepad.exe" -ErrorAction SilentlyContinue Start-Sleep -Seconds 2 Start-Process "taskkill.exe" -ArgumentList "/F /IM notepad.exe" -WindowStyle Hidden Write-Host "[+] Simulation complete. Check SIEM for alerts." -ForegroundColor Green -
Cleanup Commands:
# Cleanup: Ensure no lingering processes or attempts are left running. Stop-Process -Name "notepad" -Force -ErrorAction SilentlyContinue Write-Host "[+] Cleanup complete." -ForegroundColor Cyan