CommonMagic

First seen
2023-03-02 00:00:00
Malware type
backdoor, spyware
Family
Malware family
Profile updated
2026-07-07 13:06:58

Targeted industries: government-and-public-sector

Targeted regions: country_code:ua

Context

CommonMagic is a cyber espionage malware used to target government entities. Discovered in 2023, it focuses primarily on the Eastern European region, particularly Ukraine.

Detection coverage

  • 6 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Commonmagic (yara-rule)
  • SEKOIA_Apt_Badmagic_Commonmagic_Generic_1 (yara-rule)
  • SEKOIA_Apt_Badmagic_Commonmagic_Screenshot_Module (yara-rule)
  • SEKOIA_Apt_Badmagic_Commonmagic_Main (yara-rule)
  • SEKOIA_Apt_Badmagic_Commonmagic_Generic_2 (yara-rule)
  • SEKOIA_Apt_Badmagic_Commonmagic_Usbstealer (yara-rule)

Reports & references

  • Kaspersky — 109087 (report)
  • Kaspersky — 109722 (report)
  • Kaspersky — 109087 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Common Magic (report)

External references