IronChain Ransomware Threatens Businesses with Permanent Data Loss and Costly Downtime

IronChain Ransomware Threatens Businesses with Permanent Data Loss and Costly Downtime
IronChain is a destructive ransomware-like build that can cause permanent file loss, disrupt operations, and still fail to provide a reliable recovery path even if ransom is paid. The September 2026 sample uses four kernel drivers, SYSTEM-level persistence, and flawed encryption logic that makes it more wiper-like than trustworthy ransomware. #IronChain #BdApiUtil.sys #ProcessMonitorDriver.sys #LnvMSRIO.sys #ThrottleStop.sys

Keypoints

  • IronChain’s September 2026 build is a 9.7 MB unsigned 64-bit Windows PyInstaller executable compiled 42 seconds before first public submission.
  • The malware can cause permanent data loss because its encryption and file-handling design does not provide a reliable recovery path.
  • Four kernel drivers are bundled, but only the Baidu BdApiUtil.sys path forms a coherent process-termination chain.
  • Safetica, Lenovo, and ThrottleStop components are present, but their request contracts do not match or are never called successfully.
  • IronChain creates SYSTEM-level persistence through a scheduled task named IronChain_SYSTEM and attempts to disable defenses and services.
  • Its encryption drops the RSA private component and mutation state, making exact restoration impossible from the available artifacts.
  • Static analysis also found bugs that keep the payload reachable and narrow some intended file-encryption coverage.

MITRE Techniques

  • [T1053.005] Scheduled Task – IronChain creates and runs a SYSTEM scheduled task named IronChain_SYSTEM for persistence and continued execution (‘creation and execution of the IronChain_SYSTEM scheduled task’).
  • [T1068] Exploitation for Privilege Escalation – The sample asks for administrator rights and uses elevated execution paths to reach privileged actions (‘its intended chain asks for administrator rights’).
  • [T1543.003] Create or Modify System Process: Windows Service – It starts four driver services and uses service-like components for low-level operations (‘starts four driver services’).
  • [T1112] Modify Registry – The article does not explicitly mention registry keys, so no confirmed registry technique is listed.
  • [T1562.001] Impair Defenses: Disable or Modify Tools – IronChain attempts to disable the firewall and stop or disable EventLog and Resmon (‘attempts to disable the firewall, and attempts to stop or disable EventLog and Resmon’).
  • [T1486] Data Encrypted for Impact – The malware encrypts user files with AES-GCM and RSA-OAEP as part of destructive impact (‘encrypts user files’).
  • [T1565.001] Stored Data Manipulation – Its file-handling and encryption logic can leave critical files without a reliable recovery path and mutate bytes before encryption (‘two to seven randomized byte-mutation passes before AES-GCM encryption’).
  • [T1490] Inhibit System Recovery – It targets recovery-related components and can leave encrypted data unrecoverable (‘recovery is not guaranteed after payment’ and ‘recovery deletion’).
  • [T1070.004] File Deletion – The analysis notes recovery deletion behavior as part of the detection cluster (‘recovery deletion’).
  • [T1021.002] SMB/Windows Admin Shares – The intended chain includes spreading through shares and removable media (‘spreads through shares and removable media’).
  • [T1119] Automated Collection – It walks common user folders and queues files for processing in a broad file-encryption routine (‘first walks common user folders such as Desktop, Documents, Downloads’).
  • [T1016] System Network Configuration Discovery – The sample probes networks and performs geolocation-related lookups (‘probes networks’ and requests to ip-api.com/json/).
  • [T1047] Windows Management Instrumentation – No WMI usage is explicitly described, so this technique is not confirmed.
  • [T1218] System Binary Proxy Execution – The article does not describe proxy execution via a signed system binary, so this is not confirmed.
  • [T1211] Exploitation for Defense Evasion – The BYOVD-style process-kill path uses vulnerable driver behavior to terminate processes (‘implemented BYOVD-style process-kill path’).
  • [T1562.004] Disable or Modify System Firewall – IronChain attempts to disable the firewall (‘attempts to disable the firewall’).
  • [T1055] Process Injection – No process injection is described in the article, so this technique is not confirmed.
  • [T1005] Data from Local System – It targets local user folders and files for encryption (‘walks common user folders’).
  • [T1497.001] System Checks: System Language Discovery – No language check is described, so this technique is not confirmed.

Indicators of Compromise

  • [SHA-256 ] September IronChain executable – 09b550d66b7ce269fa577edcac54d6ba3e0f3cb5b660a2921b9372d37d52e254
  • [MD5 ] September IronChain executable – 2ac6ca0dd3cc83f5a12d12742d539fc9
  • [SHA-256 ] Baidu BdApiUtil.sys driver – d8ce0a5866178495a66d23c9587822164966111fcd34764011e907951c599711
  • [SHA-256 ] Safetica ProcessMonitorDriver.sys 11.26.18 – 5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9df
  • [SHA-256 ] Lenovo LnvMSRIO.sys 3.1.0.29 – 977d3b78bdf5723430e2e21cf1eb515a2335a0e370c76fa2dda4315ba062f429
  • [SHA-256 ] ThrottleStop 3.0.0.0 – 16f83f056177c4ec24c7e99d01ca9d9d6713bd0497eeedb777a3ffefa99c97f0
  • [Domain ] ransom portal shown to the user – ironchaindecrypt7xfzq5tclm9jzpwq72uofgy2znkdsxm54zbcu2yid.onion
  • [URL ] geolocation lookup used by the malware – http://ip-api.com/json/
  • [IP address ] sandbox-observed direct requests with no response – 103.224.182.251
  • [File name ] dropped or referenced artifacts – IronChain.hta, IronChainBg.bmp, and time.dat
  • [File path ] persistence and artifact location – %ProgramData%IRONCHAINtime.dat
  • [Device/IOCTL ] process-kill driver interface – .BdApiUtil with 0x800024B4 and a 4-byte PID
  • [Device/IOCTL ] rejected Safetica request – .STProcessMonitorDriver with 0xB822200C
  • [Device/IOCTL ] rejected Lenovo request – .BootRepair with 0x00222014
  • [String ] file marker used for detection – CHAINED_6617-382+=


Read more: https://any.run/cybersecurity-blog/ironchain-analysis/