IronLantern remediation tool for Yogi malware
IronLantern remediation tool for Yogi malware Source: https://bazaar.abuse.ch/browse/
IronLantern remediation tool for Yogi malware
Description
IronLantern remediation tool for Yogi malware Source: https://bazaar.abuse.ch/browse/
Reddit Discussion
I’ve been reverse engineering a Windows malware sample I’m calling “Yogi” and built IronLantern a defensive remediation/recovery tool from the findings.
You can find the malware sample on https://bazaar.abuse.ch/browse/ by copy pasting the malware's sha256 hash in the search bar :
sha256:ecc42df31157857f6bb17e6fd458b8bf10047a80edff10f76a3ad7126fdc6926
What I found (using DIE, pycdc, pycdas, regshot, procmon and procexp), :
- Python 3.9 / PyInstaller implant
- HKCU Run persistence via WindowsSecurity
- randomized copies under %APPDATA%\Microsoft\Crypto
- additional Startup-folder persistence
- hidden/system attributes on the Crypto copy
- JSON-based HTTP(S) command/reporting logic
- repeating-XOR ransomware
- deterministic SHA-256-derived XOR keys
- .enc file extension
- separate Telegram/TikTok/Facebook/web hashtag-trigger logic
Dynamic analysis confirmed the persistence behavior, multiple leftover copies after repeated executions, and live-process remediation.
I turned the RE into IronLantern, which handles exact-sample detection, persistence cleanup, live-process termination, quarantine/deletion, and recovery of files encrypted with the reconstructed XOR scheme.
I haven’t completed the online dynamic-analysis phase yet. Static analysis points to
https://go-ns.org.ua/ as the primary C2 endpoint
for JSON command/status traffic, with a fallback reporting endpoint at:
https://go-ns.org.ua/wp-content/themes/go-ns/send-message-to-telegram.php
The full RE report, source, and IronLantern are here:
https://github.com/bitGnome7/IronLantern
Feedback on the analysis, especially the communication/C2 side, is welcome.
I'm hoping this can help anyone who got infected...
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Domain
- null
- Newsworthiness Assessment
- {"score":38,"reasons":["external_link","newsworthy_keywords:malware","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["malware"],"foundNonNewsworthy":[]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a8f7c25acd9273b498a30b0
Added to database: 08/26/2026, 23:52:05 UTC
Last updated: 08/27/2026, 01:52:41 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.