IronLantern remediation tool for Yogi malware
Description
The IronLantern tool is a remediation and recovery utility developed to address infections by the Yogi malware, a Python 3.9/PyInstaller-based implant targeting Windows systems. Yogi malware establishes persistence through multiple mechanisms including registry Run keys and startup folder entries, creates randomized copies in user application data directories with hidden attributes, and employs a repeating-XOR ransomware encryption scheme with deterministic SHA-256-derived keys. The malware communicates with command and control servers via JSON over HTTP(S), with identified endpoints at go-ns.org.ua. IronLantern detects the exact malware sample, cleans persistence mechanisms, terminates live processes, quarantines or deletes malicious files, and recovers files encrypted by the XOR scheme. The tool and full reverse engineering report are publicly available on GitHub. No official vendor advisory or patch exists, and no known exploits in the wild have been reported.
Reddit Discussion
I’ve been reverse engineering a Windows malware sample I’m calling “Yogi” and built IronLantern a defensive remediation/recovery tool from the findings.
You can find the malware sample on https://bazaar.abuse.ch/browse/ by copy pasting the malware's sha256 hash in the search bar :
sha256:ecc42df31157857f6bb17e6fd458b8bf10047a80edff10f76a3ad7126fdc6926
What I found (using DIE, pycdc, pycdas, regshot, procmon and procexp), :
- Python 3.9 / PyInstaller implant
- HKCU Run persistence via WindowsSecurity
- randomized copies under %APPDATA%\Microsoft\Crypto
- additional Startup-folder persistence
- hidden/system attributes on the Crypto copy
- JSON-based HTTP(S) command/reporting logic
- repeating-XOR ransomware
- deterministic SHA-256-derived XOR keys
- .enc file extension
- separate Telegram/TikTok/Facebook/web hashtag-trigger logic
Dynamic analysis confirmed the persistence behavior, multiple leftover copies after repeated executions, and live-process remediation.
I turned the RE into IronLantern, which handles exact-sample detection, persistence cleanup, live-process termination, quarantine/deletion, and recovery of files encrypted with the reconstructed XOR scheme.
I haven’t completed the online dynamic-analysis phase yet. Static analysis points to
https://go-ns.org.ua/ as the primary C2 endpoint
for JSON command/status traffic, with a fallback reporting endpoint at:
https://go-ns.org.ua/wp-content/themes/go-ns/send-message-to-telegram.php
The full RE report, source, and IronLantern are here:
https://github.com/bitGnome7/IronLantern
Feedback on the analysis, especially the communication/C2 side, is welcome.
I'm hoping this can help anyone who got infected...
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Yogi is a Windows malware implant written in Python 3.9 and packaged with PyInstaller. It achieves persistence via HKCU Run registry keys and startup folder entries, placing randomized copies under %APPDATA%\Microsoft\Crypto with hidden/system attributes. The malware uses JSON-based HTTP(S) communication with C2 servers at go-ns.org.ua and employs a repeating-XOR ransomware encryption with deterministic keys derived from SHA-256. IronLantern is a defensive remediation tool developed from reverse engineering Yogi, capable of exact sample detection, persistence cleanup, live process termination, quarantine/deletion, and file recovery of XOR-encrypted files. The analysis and tool are community-shared without an official vendor patch or advisory.
Potential Impact
Yogi malware can persist on infected Windows systems, encrypt user files using a repeating-XOR ransomware method, and communicate with remote command and control servers to receive commands and report status. This can lead to data encryption and potential data loss if not remediated. However, no active exploitation in the wild has been reported, and a community-developed remediation tool exists to detect and recover from infections.
Defensive Guidance
No official vendor patch or advisory is available. The IronLantern remediation tool developed by the reverse engineer is publicly available and provides detection, persistence removal, process termination, and file recovery capabilities specific to Yogi malware. Users infected with Yogi should consider using IronLantern for remediation. Monitor the GitHub repository for updates and community feedback. Follow standard incident response procedures when handling infected systems.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":38,"reasons":["external_link","newsworthy_keywords:malware","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["malware"]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a8f7c25acd9273b498a30b0
Added to database: 08/26/2026, 23:52:05 UTC
Last enriched: 09/10/2026, 09:53:40 UTC
Last updated: 10/04/2026, 03:18:37 UTC
Views: 111
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.