Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Iron Group

Also known as: Iron Cyber Group, Rocke, tracked as, H63D, non-C282Y homozygous, the, Project Spy, Cridex, similar to Sliver, Cobalt Strike, consists of multiple components, NoFive, Plat1, U2DiskWatch, control module

Description

Iron Group emerged in the mid‑2010s and has since engineered an extensive toolkit that operates on Windows, Linux, and Android environments. Its flagship worm, Xbash, is a Python‑based agent that self‑propagates through weak credentials, installs cryptocurrency miners, encrypts files for ransom, and can delete database services (MySQL, PostgreSQL, MongoDB). In parallel, the actor runs ransomware families under the BLINDINGCAN banner—most notably IronErn440 and IronHusky—that employ a double‑extortion model: exfiltrating credentials and sensitive data before encrypting victim files.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Telecommunications
Manufacturing
Education
Healthcare
Energy
Transportation
Critical infrastructure
Media
Information technology
Retail
Aerospace
Mining
Pharmaceutical
Aviation
Maritime
Chemical
Legal services
Nuclear
Hospitality
Gaming

Targeted Countries / Regions

US
RU
KR
CN
UA
BR
GB
IN
PL
AU
MX
DE
ES
CA
JP
IL
TR
SY
TW
IT
SA
IR
FR
VN
SG
PK
AE
NL
AZ
KZ

AI Analysis

Grounded in web research
· 5 hours ago

Executive Summary

Iron Group is a hybrid adversary that blends cyber‑crime and espionage tactics to date. The group deploys cross‑platform malware—including the Xbash worm, coin‑mining payloads, and double‑extortion ransomware families such as BLINDINGCAN—to target a global portfolio of sectors, while using legitimate tunneling services to hide command‑and‑control traffic.

Goals & Targeting

Iron Group seeks both material gain from ransomware payouts or mining revenues and strategic intelligence from compromised systems. By targeting critical infrastructure, defense, and financial services worldwide—from the US, EU, and China to emerging markets such as Brazil and India—it can exploit high‑value data while spreading its operations across diverse industries with relatively low defensive barriers.

Enhanced Description

Key Capabilities

  • Cross‑platform malware development
  • Python‑based worm (Xbash) capable of self‑propagation via weak credentials
  • Dual‑purpose coin mining and ransomware delivery
  • Double‑extortion ransomware (BLINDINGCAN, IronErn440, IronHusky)
  • Persistence through WMI exploitation and custom backdoors
  • Obfuscation using PyInstaller packaging and reflective DLL injection
  • Legitimate tunneling and C2 via ngrok, DNS reverse lookups, HTTP POST endpoints

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Acquisition
Discovery
Command and Control
Exfiltration
Impact

ATT&CK Techniques

T1197 – BITS Jobs
T1059.001 – PowerShell
T1064 – Scripting
T1071.003 – DNS
T1071.001 – Web Services (HTTP/HTTPS)
T1047 – Windows Management Instrumentation (WMI)
T1055 – Process Injection
T1036 – Masquerading
T1082 – System Information Discovery
T1105 – Remote File Copy

Software / Tooling

Xbash
IronErn440
IronHusky
BLINDINGCAN
Wmiexec
Mimikatz

Campaigns & Victims

Since its first recorded activity, Iron Group has maintained a steady operational tempo that blends high‑volume ransomware campaigns with targeted espionage operations. The group demonstrates adaptability, deploying new payloads across Windows, Linux, and Android platforms while retaining legacy mechanisms such as WMI hijacking for persistence. Their campaigns often involve large‑scale double‑extortion attacks on financial services, governmental agencies, and critical infrastructure, followed by secondary intelligence gathering through covert exfiltration channels.

IOC Patterns

  • Spear‑phishing attachments or links delivering Python scripts or PowerShell bundles
  • C2 over ngrok tunnels and DNS reverse lookup via HTTP POST endpoints
  • Use of legitimate tunneling protocols (OpenVPN, SSH) for traffic obfuscation
  • Obfuscated payloads packaged with PyInstaller and reflective loading
  • Staging infrastructure on bulletproof hosting services

Recommended Actions

  • Implement multi‑factor authentication and enforce least privilege to mitigate weak credential exploitation
  • Deploy advanced endpoint detection that includes miner and ransomware signatures such as Xbash and BLINDINGCAN
  • Block outbound traffic to known tunneling domains (e.g., ngrok.com) and monitor DNS queries for reverse lookup anomalies
  • Enforce application whitelisting, especially on Windows servers, to prevent WMI‑based persistence
  • Establish regular database backups and test restoration procedures to counter database deletion tactics
  • Conduct phishing simulation training focused on Python/PowerShell payloads
  • Enable network segmentation between critical infrastructure segments and general IT networks

Suggested Tags

APT
Hybrid threat
Espionage
Ransomware
Cybercrime
Cross‑platform malware
Data exfiltration
Coin mining

Confidence Assessment

The technical details regarding Xbash, coin mining, and double‑extortion ransomware are corroborated by multiple reputable sources (Malpedia actor page, MITRE ATT&CK software entry, CyberScoop article). However, the group’s exact first‑seen and last‑seen dates remain unspecified in public intelligence. While core capabilities and common tactics are well documented, specific internal toolchains or evolving obfuscation methods may not be fully captured in current data sets.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 10 URL 1 Email Address 1 Filename 8

References

Intel Summary

14

Techniques

55

Tools

0

Campaigns

40

IOCs

0

Observed Data

2

Tactics

Tags

APT
espionage
multi-platform
unknown-sector
Iron Group
Ransomware
Cryptomining
Botnet
WMI
Backdoor
Xbash
BLINDINGCAN
Android Malware
Windows Malicious Tool
Linux Malicious Tool
Credential Theft
Double Extortion
Data Exfiltration C2
Defense Evasion
Hybrid threat
Espionage
Cybercrime
Cross‑platform malware
Data exfiltration
Coin mining

Details

Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
Jul 24, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.