Iron
- Malware type
- ransomware
- Profile updated
- 2026-07-07 13:42:12
Targeted industries: technology-and-telecommunications financial-services transportation-and-logistics
Context
It is currently unknown if Iron is indeed a new variant by the same creators of Maktub, or if it was simply inspired by the latter, by copying the design for the payment portal for example. We know the Iron ransomware has mimicked at least three ransomware families:Maktub (payment portal design) DMA Locker (Iron Unlocker, decryption tool) Satan (exclusion list)
Detection coverage
- 1 YARA rules
Detection rules
- SIGNATURE_BASE_Irontiger_Getpassword_X64 (yara-rule)
Reports & references
- bartblaze.blogspot.lu — Maktub Ransomware Possibly Rebranded As (report)
- id-ransomware.blogspot.com — Ironlocker Ransomware (report)