Incident response · DragonForce ransomware
Hit by DragonForce ransomware? Header-only damage is often the whole problem.
DragonForce decides how hard to encrypt each file based on its type and size, and on the biggest files it frequently settles for a partial pass or just the header. A virtual disk with a wrecked header will not mount and looks like a total loss. The data behind that header is usually still there.
Recognise it
How to confirm it is DragonForce.
Before anything else, keep the encrypted files and every ransom note exactly where they are. They identify the strain, and they are often the raw material a recovery works from.
- File extension
- .dragonforce_encrypted on the Conti-derived builds, though affiliates can and do customise it
- Ransom note
- A readme-style note dropped in affected folders, pointing to the group's Tor negotiation and leak site
- First seen
- December 2023, initially on BreachForums; now a large affiliate operation
- Typical entry
- Valid credentials, social engineering of help desks, and exposed remote access, followed by rapid movement to virtualisation infrastructure
Behaviour
What DragonForce does to your systems.
Full, partial or header-only
The encryptor picks a mode based on file type and size, favouring speed on large files. Header-only and partial passes are common precisely on the databases and virtual machine images that matter most.
ChaCha8 with a per-file key
A fresh session key per file, with a metadata block appended to each encrypted file holding the wrapped key, the mode used and the original size. Breaking the cipher is not a recovery path.
Built for ESXi as well as Windows
There are dedicated builds for VMware ESXi, so an affiliate who reaches the hypervisor can encrypt entire virtual servers at once rather than machine by machine.
A cartel, not a single crew
DragonForce runs as ransomware-as-a-service and white-labels its platform to other groups and affiliates. Tradecraft therefore varies a lot between incidents, and so does what you are actually dealing with.
Double extortion
Data is exfiltrated before encryption and published on a leak site to add pressure. What was actually taken is a question for the forensic timeline, not the ransom note.
Active and growing
The operation has publicly claimed hundreds of victims across 2025 and 2026, including well-publicised retail attacks where ESXi hosts were the target.
The honest answer
Can DragonForce-encrypted files be recovered?
Frequently good, and occasionally excellent. Where DragonForce has applied header-only encryption, the overwhelming majority of the file is untouched: the reason it will not open is that the structure at the front, the part an application reads first, has been scrambled. Rebuilding that structure from the surviving block map is exactly the case ScanCrypt was written for, and it is why a VHDX or VMDK that no hypervisor will mount is often far from lost.
The honest limits. Where the mode was full encryption, particularly on smaller files, there is nothing to recover without a key or a backup. The mode varies per file and per affiliate, so the only way to know your split is to measure it. There is no reliable public decryptor to plan around; check nomoreransom.org and then work the evidence.
Because the encryption mode varies file by file, measurement matters more here than with most strains. We scan a representative sample, report what proportion falls into each mode, and tell you plainly what that means for your critical systems, usually within hours of getting access.
Common questions
DragonForce, in plain terms.
Mid-incident and need a straight answer? Call 1300 004 766. A person answers, 24 hours a day.
What is the .dragonforce_encrypted file extension?
It is the extension used by the Conti-derived DragonForce builds, appended to files the ransomware has encrypted. Affiliates can change it, so a DragonForce incident does not always carry that exact extension. The ransom note and the leak-site branding are usually the more reliable identifiers. Keep both, along with the encrypted files.
Our ESXi hosts were encrypted. Is anything recoverable?
Often, yes, and this is the case worth being most careful with. DragonForce has dedicated ESXi builds, and virtual machine disks are large structured files where partial or header-only encryption leaves most of the data intact. A VMDK that will not mount is frequently rebuildable from its surviving block map. Do not delete or recreate the datastores, and do not let anyone re-provision the hosts before an assessment.
Can DragonForce files be decrypted for free?
Do not plan on it. DragonForce encrypts with ChaCha8 using a per-file session key, so the cipher itself is not the weak point. Researchers have published analyses of the family, and free tooling occasionally appears for specific builds, so it is worth checking nomoreransom.org. The dependable routes remain clean backups, snapshots, and recovering the data that was never encrypted.
Why do some of our files open and others do not?
Because the encryptor chooses a mode per file. Some files were fully encrypted, some partially, and some had only their header touched, which is why the damage looks inconsistent. That inconsistency is useful information: it tells you the recovery job is a measurement exercise, and that a meaningful share of your data may be sitting there readable.
What should we do in the first hour?
Isolate affected systems but leave them powered on, and be especially careful with virtualisation infrastructure: leave datastores exactly as they are. Keep every encrypted file and ransom note, take surviving backups offline, and start a timeline. Do not rebuild, do not run cleanup tools, and do not pay in a panic. 1300 004 766 is answered around the clock.
Not DragonForce?
The extension on your files names the strain.
If the note or extension does not match what is on this page, one of these may fit. If none of them do, call anyway: the strain shapes the recovery, but identifying it is our job, not yours.
.akira
Akira →
Consistently among the most active strains in Australia. Partial encryption by design.
random extension
Qilin →
The most active operation of 2026. Every victim gets a unique file extension.
.inc
INC Ransom →
Subject of a 2026 ACSC joint advisory. Heavy targeting of Australian healthcare.
.fog / .flocked
Fog →
Education-focused, enters via VPN credentials, attacks backups first.
.safepay
SafePay →
Encryption depth is a setting, and operators pick shallow. Enters on valid VPN and RDP credentials.
Or start from ransomware recovery, which covers the method whatever the strain turns out to be.
Right now
The first hours decide what can be saved.
Isolate the machines, keep the encrypted files, take backups offline, and call before anything gets rebuilt. Australian incident response, answered by a real person.