Attackers compromised IObit’s forum infrastructure and used it to send members a fake promotional email offering a free one-year license, directing recipients to a malicious ZIP archive hosted on an IObit forum domain. The archive bundled legitimate, digitally signed IObit License Manager components with a trojanized IObitUnlocker.dll, causing DeroHE ransomware to execute when License Manager.exe was launched. The malware established persistence, added Windows Defender exclusions, encrypted files with the .DeroHE extension, and dropped ransom notes demanding 200 DERO from victims while also claiming IObit could pay 100,000 DERO to recover all affected systems.
Victim reports described severe damage, including more than 121,000 files renamed with the .DeroHE extension and many files corrupted across images, archives, PDFs, and source code, while some plain-text files were partially recoverable by restoring the .txt extension. Reporting also indicated the forum likely remained compromised after the ransomware campaign, with malicious scripts on the site triggering browser-notification abuse, redirects, and adult-content advertisements; the affected forum was identified as running vBulletin 5.6.1, a version reported to have a known vulnerability that could allow remote takeover.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Reporting stated that the IObit forums still appeared compromised after the ransomware distribution, with missing pages injecting scripts that pushed browser-notification scams and redirected visitors to unwanted or adult content. The articles also noted the forum was reportedly running vBulletin 5.6.1, a version said to have a known vulnerability.
Analysis cited in reporting found that DeroHE established persistence via an autorun entry, added Windows Defender exclusions, encrypted files with the .DeroHE extension, and dropped HTML ransom files on victims' desktops. The ransom note demanded 200 DERO coins from victims and said IObit could pay 100,000 DERO coins to decrypt all affected systems.
A forum user reported that after running the downloaded IObit-linked patch, more than 121,000 files were renamed with the .DeroHE extension and many files, including images, archives, PDFs, and source code, were corrupted. The user also said Windows Defender did not detect the malware and that IObit's website appeared down when they tried to report the incident.
Attackers used IObit's forum infrastructure to send forum members emails offering a free one-year license and linked them to a malicious promo page and ZIP archive hosted on the IObit forum domain. Running the package loaded a trojanized IObitUnlocker.dll and installed the DeroHE ransomware.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
malwaretips.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.