Skip to main content

IronLantern remediation tool for Yogi malware

0
Medium
Published: 08/26/2026 (08/26/2026, 15:02:45 UTC)
Source: Reddit Cybersecurity

Description

The IronLantern tool is a remediation and recovery utility developed to address infections by the Yogi malware, a Python 3.9/PyInstaller-based implant targeting Windows systems. Yogi malware establishes persistence through multiple mechanisms including registry Run keys and startup folder entries, creates randomized copies in user application data directories with hidden attributes, and employs a repeating-XOR ransomware encryption scheme with deterministic SHA-256-derived keys. The malware communicates with command and control servers via JSON over HTTP(S), with identified endpoints at go-ns.org.ua. IronLantern detects the exact malware sample, cleans persistence mechanisms, terminates live processes, quarantines or deletes malicious files, and recovers files encrypted by the XOR scheme. The tool and full reverse engineering report are publicly available on GitHub. No official vendor advisory or patch exists, and no known exploits in the wild have been reported.

Reddit Discussion

r/cybersecurity·posted by u/bitGnome_7
00

I’ve been reverse engineering a Windows malware sample I’m calling “Yogi” and built IronLantern a defensive remediation/recovery tool from the findings.

You can find the malware sample on https://bazaar.abuse.ch/browse/ by copy pasting the malware's sha256 hash in the search bar :
sha256:ecc42df31157857f6bb17e6fd458b8bf10047a80edff10f76a3ad7126fdc6926

What I found (using DIE, pycdc, pycdas, regshot, procmon and procexp), :

- Python 3.9 / PyInstaller implant

- HKCU Run persistence via WindowsSecurity

- randomized copies under %APPDATA%\Microsoft\Crypto

- additional Startup-folder persistence

- hidden/system attributes on the Crypto copy

- JSON-based HTTP(S) command/reporting logic

- repeating-XOR ransomware

- deterministic SHA-256-derived XOR keys

- .enc file extension

- separate Telegram/TikTok/Facebook/web hashtag-trigger logic

Dynamic analysis confirmed the persistence behavior, multiple leftover copies after repeated executions, and live-process remediation.

I turned the RE into IronLantern, which handles exact-sample detection, persistence cleanup, live-process termination, quarantine/deletion, and recovery of files encrypted with the reconstructed XOR scheme.

I haven’t completed the online dynamic-analysis phase yet. Static analysis points to
https://go-ns.org.ua/ as the primary C2 endpoint

for JSON command/status traffic, with a fallback reporting endpoint at:
https://go-ns.org.ua/wp-content/themes/go-ns/send-message-to-telegram.php

The full RE report, source, and IronLantern are here:
https://github.com/bitGnome7/IronLantern

Feedback on the analysis, especially the communication/C2 side, is welcome.

I'm hoping this can help anyone who got infected...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 09:53:40 UTC

Technical Analysis

Yogi is a Windows malware implant written in Python 3.9 and packaged with PyInstaller. It achieves persistence via HKCU Run registry keys and startup folder entries, placing randomized copies under %APPDATA%\Microsoft\Crypto with hidden/system attributes. The malware uses JSON-based HTTP(S) communication with C2 servers at go-ns.org.ua and employs a repeating-XOR ransomware encryption with deterministic keys derived from SHA-256. IronLantern is a defensive remediation tool developed from reverse engineering Yogi, capable of exact sample detection, persistence cleanup, live process termination, quarantine/deletion, and file recovery of XOR-encrypted files. The analysis and tool are community-shared without an official vendor patch or advisory.

Potential Impact

Yogi malware can persist on infected Windows systems, encrypt user files using a repeating-XOR ransomware method, and communicate with remote command and control servers to receive commands and report status. This can lead to data encryption and potential data loss if not remediated. However, no active exploitation in the wild has been reported, and a community-developed remediation tool exists to detect and recover from infections.

Defensive Guidance

No official vendor patch or advisory is available. The IronLantern remediation tool developed by the reverse engineer is publicly available and provides detection, persistence removal, process termination, and file recovery capabilities specific to Yogi malware. Users infected with Yogi should consider using IronLantern for remediation. Monitor the GitHub repository for updates and community feedback. Follow standard incident response procedures when handling infected systems.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":38,"reasons":["external_link","newsworthy_keywords:malware","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["malware"]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a8f7c25acd9273b498a30b0

Added to database: 08/26/2026, 23:52:05 UTC

Last enriched: 09/10/2026, 09:53:40 UTC

Last updated: 10/04/2026, 03:18:37 UTC

Views: 111

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses