Iron ransomware is a Windows ransomware family observed in 2018 and named after its decryption utility branding, IronUnlocker. It appears to be either a rebranded descendant of, or heavily inspired by, Maktub ransomware, while also borrowing design elements seen in other ransomware families such as DMA Locker and Satan. Attribution remains uncertain, but the malware has been assessed as code-distinct enough that a direct one-to-one identification with Maktub is not definitive.
Iron encrypts a broad set of user and business data types and appends a dedicated extension to encrypted files. It deletes original files after encryption and empties the recycle bin, increasing recovery difficulty. The malware embeds an RSA public key, generates host-specific values, and communicates with command-and-control infrastructure to register the victim and obtain payment-related data, including a victim-specific cryptocurrency payment destination. It also creates a GUID-based mutex to prevent reinfection and stores operational values locally for tracking.
The ransomware excludes numerous system, browser, temporary, and security-related directories from encryption, including folders associated with Qihoo 360 products, indicating deliberate avoidance of destabilizing the host or interfering with certain security software. Unlike some other ransomware families, Iron was not observed deleting Shadow Volume Copies or restore points, leaving open the possibility of partial recovery through native snapshots or forensic recovery tools in some cases.
Analysis of the family identified Chinese Simplified language resources and exclusion logic referencing Chinese security products, suggesting the developer may be a Chinese speaker. Iron has also been discussed as a possible spin-off from the broader Satan ransomware ecosystem, but that relationship is not established with high confidence. The malware is best characterized as a Windows ransomware strain with traits overlapping several contemporaneous crimeware families.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A likely related ransomware family mentioned as possibly developed by the same group behind Satan, DBGer, Lucky, and 5ss5c, with slight TTP overlap noted.
Referenced as a ransomware strain/group inspired by Satan code.
Iron is referenced as a ransomware family possibly related to or spun off from Satan, noted here for using VMProtect and having a similar exclusion list.
A ransomware family that appears to be a possible new variant or rebranding inspired by Maktub. It encrypts files, appends the .encry extension, deletes original files, empties the recycle bin, contacts a C2 server, stores values in HKCU\Software\CryptoA, and uses an embedded RSA public key. It does not remove Shadow Volume Copies or Restore Points.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.