IronChain Ransomware’s Encryption Design May Make Files Unrecoverable

Summary
Analysis of a September 2026 IronChain build finds encryption that lacks the key material needed for reliable restoration, four bundled drivers but only one matching process-kill interface, and code flaws that alter execution and file targeting.
Key points
- The analyzed IronChain build appeared in public malware telemetry on September 12, 2026; researchers examined its artifacts using static analysis.
- The malware retains only the RSA public key and discards random mutation state, leaving no deterministic recovery path in the analyzed artifacts; ransom payment offers no technical guarantee of restoration.
- Four kernel drivers are bundled, but only the Baidu driver’s device, control code, and input length match the malware’s process-termination request. Static analysis does not prove the driver ran successfully.
- A bare exception handler catches the program’s `SystemExit` calls, allowing execution to continue after intended exits and potentially leaving overlapping processes.
- An undefined variable interrupts the malware’s broader file-targeting routine, though files already queued from user folders and a separate raw-disk thread may still be affected.
- Defenders are advised to monitor for the `IronChain_SYSTEM` task and driver activity, use vulnerable-driver protections, isolate suspected hosts, preserve evidence, and assess disk damage before rebooting.
- The analysis found no evidence of a verified victim, named actor, working command-and-control server, successful driver loading, or successful disk writes.
Article Details
- Attack Vectors
- IronChain attempts UAC elevation and creates and runs the IronChain_SYSTEM scheduled task with SYSTEM privileges.
- The sample stages four kernel drivers. Its Baidu BdApiUtil.sys process-termination request matches the bundled driver's device, IOCTL, and input length; runtime success was not verified. Its Safetica and Lenovo requests do not match their bundled drivers, and the configured ThrottleStop operation is never sent.
- IronChain attempts to impair security and recovery, encrypt user files, damage a disk through raw access, spread through shares and removable media, and force a shutdown. Static analysis does not establish that every attempted action succeeded.
- Its encryption discards the RSA private component and randomized mutation state needed for exact restoration. A variable-name error normally prevents the later, broader file-targeting pass.
- Defensive Notes
- Hunt for the combined pattern of four driver resources, IronChain_SYSTEM or IronChainSecurity, the associated kernel services, and BdApiUtil requests using IOCTL 0x800024B4 with a four-byte PID.
- Investigate clustered recovery-deletion, firewall-disablement, EventLog-suppression, and raw-disk-access activity. Test and tune the research package's YARA rule and Sigma documents before deployment.
- If infection is suspected, isolate the host from networks and removable media. Assess possible boot-disk damage before a routine reboot, preserve evidence where policy permits, and rebuild from known-good media if raw writes may have succeeded.
- Use compatible vulnerable-driver blocking and application-control protections, inventory the four driver families while accounting for legitimate installations, and maintain tested, isolated backups.
- Do not treat the observed shared IP address or the legitimate geolocation service as confirmed IronChain C2 or block them globally based on this case alone.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| MD5 | 2ac6ca0dd3cc83f5a12d12742d539fc9 | MD5 of the analyzed September IronChain sample. |
| SHA256 | 09b550d66b7ce269fa577edcac54d6ba3e0f3cb5b660a2921b9372d37d52e254 | SHA-256 of the analyzed September IronChain sample. |
| SHA256 | 16f83f056177c4ec24c7e99d01ca9d9d6713bd0497eeedb777a3ffefa99c97f0 | Hash listed among the article's primary IronChain executable and driver-artifact indicators; the extracted table does not unambiguously associate this value with a specific row. |
| SHA256 | 5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9df | Hash listed among the article's primary IronChain executable and driver-artifact indicators; the extracted table does not unambiguously associate this value with a specific row. |
| SHA256 | 977d3b78bdf5723430e2e21cf1eb515a2335a0e370c76fa2dda4315ba062f429 | Hash listed among the article's primary IronChain executable and driver-artifact indicators; the extracted table does not unambiguously associate this value with a specific row. |
| SHA256 | d8ce0a5866178495a66d23c9587822164966111fcd34764011e907951c599711 | Hash listed among the article's primary IronChain executable and artifact indicators; the extracted table does not unambiguously associate this value with a specific row. |
MITRE ATT&CK
T1053.005 · Scheduled TaskThe public sandbox session records creation and execution of the IronChain_SYSTEM scheduled task.T1486 · Data Encrypted for ImpactIronChain encrypts targeted files, but its design does not retain the information needed for deterministic restoration.T1490 · Inhibit System RecoveryRecovery deletion is identified among IronChain's destructive actions and detection signals.T1529 · System Shutdown/RebootThe reconstructed intended payload flow ends by forcing a shutdown; the article does not verify that it occurred during execution.T1543.003 · Windows ServiceIronChain attempts to start driver services as part of its staged kernel-driver workflow.T1548.002 · Bypass User Account ControlIronChain attempts to request UAC elevation before continuing into its payload.T1562.001 · Disable or Modify ToolsIronChain attempts to stop or disable EventLog and Resmon and has a matching Baidu driver interface intended to terminate security processes; successful termination was not verified.T1562.004 · Disable or Modify System FirewallThe public sandbox session shows IronChain attempting to disable the firewall.
CVE
CVE-2024-51324NVD’s CVE-2024-51324 description names a different Baidu Antivirus product version, so mapping this exact hash to that CVE should remain qualified even though the process-kill primitive itself is clear.CVE-2025-70795Safetica’s CVE-2025-70795 advisory explains the residual BYOVD exposure and its removal in later versions; CERT/CC VU#818729 provides related background.CVE-2025-7771Public work, including Kaspersky’s ThrottleStop analysis and NVD CVE-2025-7771, makes the driver relevant to defenders.CVE-2025-8061Version 3.1.0.29 falls in the range discussed in LEN-200860 and Quarkslab’s CVE-2025-8061 analysis.
People
Malware
Vendors
ANY.RUNANY.RUN sandbox session de26bdeb BaiduBaidu BdApiUtil.sys 4.6.1.65082 LenovoLenovo LnvMSRIO.sys 3.1.0.29, stored as BootRepair.sys MicrosoftUse Microsoft’s vulnerable-driver blocklist, the Defender ASR rule for abused drivers, WDAC or App Control policies, and Core Isolation Memory Integrity where compatible.SafeticaSafetica: Close, but Rejected Twice
Products
ANY.RUN Interactive SandboxApp ControlUse Microsoft’s vulnerable-driver blocklist, the Defender ASR rule for abused drivers, WDAC or App Control policies, and Core Isolation Memory Integrity where compatible.Baidu AntivirusNVD’s CVE-2024-51324 description names a different Baidu Antivirus product version, so mapping this exact hash to that CVE should remain qualified even though the process-kill primitive itself is clear.Core Isolation Memory IntegrityUse Microsoft’s vulnerable-driver blocklist, the Defender ASR rule for abused drivers, WDAC or App Control policies, and Core Isolation Memory Integrity where compatible.DefenderUse Microsoft’s vulnerable-driver blocklist, the Defender ASR rule for abused drivers, WDAC or App Control policies, and Core Isolation Memory Integrity where compatible.Microsoft WindowsThe file is a 9.7 MB unsigned, 64-bit Windows program packaged with PyInstaller.ThrottleStopThrottleStop ThrottleStop.sys3.0.0.0 WDACUse Microsoft’s vulnerable-driver blocklist, the Defender ASR rule for abused drivers, WDAC or App Control policies, and Core Isolation Memory Integrity where compatible.