The IObit Forum DeroHE Ransomware Attack

Updated 5 Oct 2026 · Incident date 16 Jan 2021 · vendor binary

Packagefree-iobit-license-promo.zip - a repackaged IObit License Manager distributed through the hacked IObit forum
FileIObitUnlocker.dll, replaced with an unsigned malicious...

In January 2021, attackers hacked the IObit forum and used it to spread a zip file named free-iobit-license-promo.zip. The zip held a copy of IObit License Manager with one changed file, IObitUnlocker.dll. That DLL installed DeroHE ransomware.

BleepingComputer reports that the attackers sent emails that offered a free one-year license to IObit forum members.

What happened

Attackers broke into the IObit forum and sent a fake license promotion to forum members. BleepingComputer dates the attack to the weekend before 19 January 2021. It says the forum ran vBulletin 5.6.1, an outdated version with a known SQL injection flaw.

The email offered a free one-year license for IObit products. A Get it Now button led to a download page. The zip file sat on IObit's own forum domain. BleepingComputer reports that the zip held digitally signed IObit files and one trojanized DLL, IObitUnlocker.dll, which was unsigned.

When the victim ran License Manager, the DLL installed the ransomware as C:\Program Files (x86)\IObit\iobit.dll. It then did the following:

The ransom notes are FILES_ENCRYPTED.html and READ_TO_DECRYPT.html. The attackers asked for 200 DERO coins, about 100 US dollars, through a Tor site. BleepingComputer says IObit did not reply to its questions. Hackread reports that the forum pages returned 404 errors and showed unwanted browser notification prompts.

Affected versions

The sources name one bad package and one bad file. They do not give a version number for the fake License Manager.

The genuine IObit License Manager package is the clean copy to compare against. The IObit signature on the other files in the zip did not protect the user. Only the DLL was changed.

Indicators of compromise

How to check

Look for the dropped DLL, the extension, and the Defender exclusions. Run these in PowerShell.

Test-Path 'C:\Program Files (x86)\IObit\iobit.dll'; Get-MpPreference | Select-Object -ExpandProperty ExclusionExtension

Then search for encrypted files and the ransom notes.

Get-ChildItem C:\ -Recurse -Include *.DeroHE,FILES_ENCRYPTED.html,READ_TO_DECRYPT.html -ErrorAction SilentlyContinue

Check the signature of any copy of IObitUnlocker.dll. The trojanized file is unsigned.

Get-AuthenticodeSignature .\IObitUnlocker.dll

What to do now

  1. Disconnect an infected computer from the network.
  2. Remove the autorun entry and the Defender exclusions that the malware added.
  3. Restore files from a backup taken before the infection.
  4. Delete free-iobit-license-promo.zip from every computer.
  5. Check unsolicited license offers against the vendor's own channels before you download anything.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old free-iobit-license-promo.zip-prev --new free-iobit-license-promo.zip-current
files scanned: 73

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    IObitUnlocker.dll
           It now downloads from the internet and runs other programs. It did not before.

Frequently asked questions

What was the IObit forum ransomware attack?

Attackers hacked the IObit forum in January 2021 and spread a fake free-license zip. The zip held a trojanized IObitUnlocker.dll that installed DeroHE ransomware.

How much did the DeroHE ransomware ask for?

BleepingComputer reports a demand of 200 DERO coins, about 100 US dollars, paid through a Tor site.

Sources

  1. bleepingcomputer.com/news/security/iobit-forums-hacked-to-spread-ransomware-to-its-members/
  2. hackread.com/iobit-forum-hacked-spread-derohe-ransomware/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free