logo

Ironchain CTI Report

ID: b79e3fd5-5d8b-4539-9d97-115a935ce109

STIX ID: report--b79e3fd5-5d8b-4539-9d97-115a935ce109

Threat Score

92/100

Uploaded: 2026-06-10

Created by: dogesec

TLP:CLEAR
...
...
Technical analysis of IronChain 3.0: a Windows x64 PyInstaller ransomware-like wiper that applies an irreversible multi-layer byte-shift before intermittent AES-GCM, generates RSA keys only in memory (never exfiltrated), overwrites the NTFS MFT and BIOS/UEFI boot components, and propagates via SMB/WMI with extensive persistence; the report concludes recovery is impossible and recommends containment and recovery from backups.