Also known as: Iron Cyber Group, Rocke, tracked as, H63D, non-C282Y homozygous, the, Project Spy, Cridex, similar to Sliver, Cobalt Strike, consists of multiple components, NoFive, Plat1, U2DiskWatch, control module
Iron Group emerged in the mid‑2010s and has since engineered an extensive toolkit that operates on Windows, Linux, and Android environments. Its flagship worm, Xbash, is a Python‑based agent that self‑propagates through weak credentials, installs cryptocurrency miners, encrypts files for ransom, and can delete database services (MySQL, PostgreSQL, MongoDB). In parallel, the actor runs ransomware families under the BLINDINGCAN banner—most notably IronErn440 and IronHusky—that employ a double‑extortion model: exfiltrating credentials and sensitive data before encrypting victim files.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Iron Group is a hybrid adversary that blends cyber‑crime and espionage tactics to date. The group deploys cross‑platform malware—including the Xbash worm, coin‑mining payloads, and double‑extortion ransomware families such as BLINDINGCAN—to target a global portfolio of sectors, while using legitimate tunneling services to hide command‑and‑control traffic.
Goals & Targeting
Iron Group seeks both material gain from ransomware payouts or mining revenues and strategic intelligence from compromised systems. By targeting critical infrastructure, defense, and financial services worldwide—from the US, EU, and China to emerging markets such as Brazil and India—it can exploit high‑value data while spreading its operations across diverse industries with relatively low defensive barriers.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its first recorded activity, Iron Group has maintained a steady operational tempo that blends high‑volume ransomware campaigns with targeted espionage operations. The group demonstrates adaptability, deploying new payloads across Windows, Linux, and Android platforms while retaining legacy mechanisms such as WMI hijacking for persistence. Their campaigns often involve large‑scale double‑extortion attacks on financial services, governmental agencies, and critical infrastructure, followed by secondary intelligence gathering through covert exfiltration channels.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The technical details regarding Xbash, coin mining, and double‑extortion ransomware are corroborated by multiple reputable sources (Malpedia actor page, MITRE ATT&CK software entry, CyberScoop article). However, the group’s exact first‑seen and last‑seen dates remain unspecified in public intelligence. While core capabilities and common tactics are well documented, specific internal toolchains or evolving obfuscation methods may not be fully captured in current data sets.
No campaigns linked yet.
No observed data linked yet.
14
Techniques
55
Tools
0
Campaigns
40
IOCs
0
Observed Data
2
Tactics