The IObit Forum DeroHE Ransomware Attack
Updated 5 Oct 2026 · Incident date 16 Jan 2021 · vendor binary
free-iobit-license-promo.zip - a repackaged IObit License Manager distributed through the hacked IObit forumIObitUnlocker.dll, replaced with an unsigned malicious...In January 2021, attackers hacked the IObit forum and used it to spread a zip file named free-iobit-license-promo.zip. The zip held a copy of IObit License Manager with one changed file, IObitUnlocker.dll. That DLL installed DeroHE ransomware.
BleepingComputer reports that the attackers sent emails that offered a free one-year license to IObit forum members.
What happened
Attackers broke into the IObit forum and sent a fake license promotion to forum members. BleepingComputer dates the attack to the weekend before 19 January 2021. It says the forum ran vBulletin 5.6.1, an outdated version with a known SQL injection flaw.
The email offered a free one-year license for IObit products. A Get it Now button led to a download page. The zip file sat on IObit's own forum domain. BleepingComputer reports that the zip held digitally signed IObit files and one trojanized DLL, IObitUnlocker.dll, which was unsigned.
When the victim ran License Manager, the DLL installed the ransomware as C:\Program Files (x86)\IObit\iobit.dll. It then did the following:
- Added an autorun registry entry named IObit License Manager.
- Added Windows Defender exclusions for
.dllfiles,rundll32.exe, and temp folders. - Showed a fake message that said the process can take longer than expected and asked the user to keep the computer on.
- Encrypted files and added the
.DeroHEextension.
The ransom notes are FILES_ENCRYPTED.html and READ_TO_DECRYPT.html. The attackers asked for 200 DERO coins, about 100 US dollars, through a Tor site. BleepingComputer says IObit did not reply to its questions. Hackread reports that the forum pages returned 404 errors and showed unwanted browser notification prompts.
Affected versions
The sources name one bad package and one bad file. They do not give a version number for the fake License Manager.
- Package:
free-iobit-license-promo.zip - Changed file:
IObitUnlocker.dll, unsigned - Main program in the zip: IObit License Manager.exe
The genuine IObit License Manager package is the clean copy to compare against. The IObit signature on the other files in the zip did not protect the user. Only the DLL was changed.
Indicators of compromise
- File:
free-iobit-license-promo.zip - Dropped file:
C:\Program Files (x86)\IObit\iobit.dll - Autorun registry entry named
IObit License Manager - Defender exclusions for
.dll,rundll32.exe, and temp folders - Encrypted files with the
.DeroHEextension - Ransom notes
FILES_ENCRYPTED.htmlandREAD_TO_DECRYPT.html - Payment site:
deropayysnkrl5xu7ic5fdprz5ixgdwy6ikxe2g3mh2erikudscrkpqd.onion
How to check
Look for the dropped DLL, the extension, and the Defender exclusions. Run these in PowerShell.
Test-Path 'C:\Program Files (x86)\IObit\iobit.dll'; Get-MpPreference | Select-Object -ExpandProperty ExclusionExtension
Then search for encrypted files and the ransom notes.
Get-ChildItem C:\ -Recurse -Include *.DeroHE,FILES_ENCRYPTED.html,READ_TO_DECRYPT.html -ErrorAction SilentlyContinue
Check the signature of any copy of IObitUnlocker.dll. The trojanized file is unsigned.
Get-AuthenticodeSignature .\IObitUnlocker.dll
What to do now
- Disconnect an infected computer from the network.
- Remove the autorun entry and the Defender exclusions that the malware added.
- Restore files from a backup taken before the infection.
- Delete
free-iobit-license-promo.zipfrom every computer. - Check unsolicited license offers against the vendor's own channels before you download anything.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 73 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED IObitUnlocker.dll It now downloads from the internet and runs other programs. It did not before.
Frequently asked questions
What was the IObit forum ransomware attack?
Attackers hacked the IObit forum in January 2021 and spread a fake free-license zip. The zip held a trojanized IObitUnlocker.dll that installed DeroHE ransomware.
How much did the DeroHE ransomware ask for?
BleepingComputer reports a demand of 200 DERO coins, about 100 US dollars, paid through a Tor site.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.