Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

IronLantern remediation tool for Yogi malware

0
Medium
Published: 08/26/2026 (08/26/2026, 15:02:45 UTC)
Source: Reddit Cybersecurity

Description

IronLantern remediation tool for Yogi malware Source: https://bazaar.abuse.ch/browse/

Reddit Discussion

r/cybersecurity·posted by u/bitGnome_7
00

I’ve been reverse engineering a Windows malware sample I’m calling “Yogi” and built IronLantern a defensive remediation/recovery tool from the findings.

You can find the malware sample on https://bazaar.abuse.ch/browse/ by copy pasting the malware's sha256 hash in the search bar :
sha256:ecc42df31157857f6bb17e6fd458b8bf10047a80edff10f76a3ad7126fdc6926

What I found (using DIE, pycdc, pycdas, regshot, procmon and procexp), :

- Python 3.9 / PyInstaller implant

- HKCU Run persistence via WindowsSecurity

- randomized copies under %APPDATA%\Microsoft\Crypto

- additional Startup-folder persistence

- hidden/system attributes on the Crypto copy

- JSON-based HTTP(S) command/reporting logic

- repeating-XOR ransomware

- deterministic SHA-256-derived XOR keys

- .enc file extension

- separate Telegram/TikTok/Facebook/web hashtag-trigger logic

Dynamic analysis confirmed the persistence behavior, multiple leftover copies after repeated executions, and live-process remediation.

I turned the RE into IronLantern, which handles exact-sample detection, persistence cleanup, live-process termination, quarantine/deletion, and recovery of files encrypted with the reconstructed XOR scheme.

I haven’t completed the online dynamic-analysis phase yet. Static analysis points to
https://go-ns.org.ua/ as the primary C2 endpoint

for JSON command/status traffic, with a fallback reporting endpoint at:
https://go-ns.org.ua/wp-content/themes/go-ns/send-message-to-telegram.php

The full RE report, source, and IronLantern are here:
https://github.com/bitGnome7/IronLantern

Feedback on the analysis, especially the communication/C2 side, is welcome.

I'm hoping this can help anyone who got infected...

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":38,"reasons":["external_link","newsworthy_keywords:malware","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["malware"],"foundNonNewsworthy":[]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a8f7c25acd9273b498a30b0

Added to database: 08/26/2026, 23:52:05 UTC

Last updated: 08/27/2026, 01:52:41 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses