Iron

Malware type
ransomware
Profile updated
2026-07-07 13:42:12

Targeted industries: technology-and-telecommunications financial-services transportation-and-logistics

Context

It is currently unknown if Iron is indeed a new variant by the same creators of Maktub, or if it was simply inspired by the latter, by copying the design for the payment portal for example. We know the Iron ransomware has mimicked at least three ransomware families:Maktub (payment portal design) DMA Locker (Iron Unlocker, decryption tool) Satan (exclusion list)

Detection coverage

  • 1 YARA rules

Detection rules

  • SIGNATURE_BASE_Irontiger_Getpassword_X64 (yara-rule)

Reports & references

  • bartblaze.blogspot.lu — Maktub Ransomware Possibly Rebranded As (report)
  • id-ransomware.blogspot.com — Ironlocker Ransomware (report)

External references