IronChain is a destructive ransomware-like build that can cause permanent file loss, disrupt operations, and still fail to provide a reliable recovery path even if ransom is paid. The September 2026 sample uses four kernel drivers, SYSTEM-level persistence, and flawed encryption logic that makes it more wiper-like than trustworthy ransomware. #IronChain #BdApiUtil.sys #ProcessMonitorDriver.sys #LnvMSRIO.sys #ThrottleStop.sys
Keypoints
- IronChainâs September 2026 build is a 9.7 MB unsigned 64-bit Windows PyInstaller executable compiled 42 seconds before first public submission.
- The malware can cause permanent data loss because its encryption and file-handling design does not provide a reliable recovery path.
- Four kernel drivers are bundled, but only the Baidu BdApiUtil.sys path forms a coherent process-termination chain.
- Safetica, Lenovo, and ThrottleStop components are present, but their request contracts do not match or are never called successfully.
- IronChain creates SYSTEM-level persistence through a scheduled task named IronChain_SYSTEM and attempts to disable defenses and services.
- Its encryption drops the RSA private component and mutation state, making exact restoration impossible from the available artifacts.
- Static analysis also found bugs that keep the payload reachable and narrow some intended file-encryption coverage.
MITRE Techniques
- [T1053.005] Scheduled Task â IronChain creates and runs a SYSTEM scheduled task named IronChain_SYSTEM for persistence and continued execution (âcreation and execution of the IronChain_SYSTEM scheduled taskâ).
- [T1068] Exploitation for Privilege Escalation â The sample asks for administrator rights and uses elevated execution paths to reach privileged actions (âits intended chain asks for administrator rightsâ).
- [T1543.003] Create or Modify System Process: Windows Service â It starts four driver services and uses service-like components for low-level operations (âstarts four driver servicesâ).
- [T1112] Modify Registry â The article does not explicitly mention registry keys, so no confirmed registry technique is listed.
- [T1562.001] Impair Defenses: Disable or Modify Tools â IronChain attempts to disable the firewall and stop or disable EventLog and Resmon (âattempts to disable the firewall, and attempts to stop or disable EventLog and Resmonâ).
- [T1486] Data Encrypted for Impact â The malware encrypts user files with AES-GCM and RSA-OAEP as part of destructive impact (âencrypts user filesâ).
- [T1565.001] Stored Data Manipulation â Its file-handling and encryption logic can leave critical files without a reliable recovery path and mutate bytes before encryption (âtwo to seven randomized byte-mutation passes before AES-GCM encryptionâ).
- [T1490] Inhibit System Recovery â It targets recovery-related components and can leave encrypted data unrecoverable (ârecovery is not guaranteed after paymentâ and ârecovery deletionâ).
- [T1070.004] File Deletion â The analysis notes recovery deletion behavior as part of the detection cluster (ârecovery deletionâ).
- [T1021.002] SMB/Windows Admin Shares â The intended chain includes spreading through shares and removable media (âspreads through shares and removable mediaâ).
- [T1119] Automated Collection â It walks common user folders and queues files for processing in a broad file-encryption routine (âfirst walks common user folders such as Desktop, Documents, Downloadsâ).
- [T1016] System Network Configuration Discovery â The sample probes networks and performs geolocation-related lookups (âprobes networksâ and requests to ip-api.com/json/).
- [T1047] Windows Management Instrumentation â No WMI usage is explicitly described, so this technique is not confirmed.
- [T1218] System Binary Proxy Execution â The article does not describe proxy execution via a signed system binary, so this is not confirmed.
- [T1211] Exploitation for Defense Evasion â The BYOVD-style process-kill path uses vulnerable driver behavior to terminate processes (âimplemented BYOVD-style process-kill pathâ).
- [T1562.004] Disable or Modify System Firewall â IronChain attempts to disable the firewall (âattempts to disable the firewallâ).
- [T1055] Process Injection â No process injection is described in the article, so this technique is not confirmed.
- [T1005] Data from Local System â It targets local user folders and files for encryption (âwalks common user foldersâ).
- [T1497.001] System Checks: System Language Discovery â No language check is described, so this technique is not confirmed.
Indicators of Compromise
- [SHA-256 ] September IronChain executable â 09b550d66b7ce269fa577edcac54d6ba3e0f3cb5b660a2921b9372d37d52e254
- [MD5 ] September IronChain executable â 2ac6ca0dd3cc83f5a12d12742d539fc9
- [SHA-256 ] Baidu BdApiUtil.sys driver â d8ce0a5866178495a66d23c9587822164966111fcd34764011e907951c599711
- [SHA-256 ] Safetica ProcessMonitorDriver.sys 11.26.18 â 5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9df
- [SHA-256 ] Lenovo LnvMSRIO.sys 3.1.0.29 â 977d3b78bdf5723430e2e21cf1eb515a2335a0e370c76fa2dda4315ba062f429
- [SHA-256 ] ThrottleStop 3.0.0.0 â 16f83f056177c4ec24c7e99d01ca9d9d6713bd0497eeedb777a3ffefa99c97f0
- [Domain ] ransom portal shown to the user â ironchaindecrypt7xfzq5tclm9jzpwq72uofgy2znkdsxm54zbcu2yid.onion
- [URL ] geolocation lookup used by the malware â http://ip-api.com/json/
- [IP address ] sandbox-observed direct requests with no response â 103.224.182.251
- [File name ] dropped or referenced artifacts â IronChain.hta, IronChainBg.bmp, and time.dat
- [File path ] persistence and artifact location â %ProgramData%IRONCHAINtime.dat
- [Device/IOCTL ] process-kill driver interface â .BdApiUtil with 0x800024B4 and a 4-byte PID
- [Device/IOCTL ] rejected Safetica request â .STProcessMonitorDriver with 0xB822200C
- [Device/IOCTL ] rejected Lenovo request â .BootRepair with 0x00222014
- [String ] file marker used for detection â CHAINED_6617-382+=
Read more: https://any.run/cybersecurity-blog/ironchain-analysis/