Magniber

First seen
2017-10-01 00:00:00
Malware type
ransomware, exploit-kit
Family
Malware family
Last IoC activity
2026-07-11 06:02:55
Profile updated
2026-07-07 15:10:52

Targeted regions: country_code:kr

Context

According to TXOne, The Magniber ransomware was first identified in late 2017 when it was discovered using the Magnitude Exploit Kit to conduct malvertising attacks against users in South Korea. However, it has remained active since then, continually updating its tactics by employing new obfuscation techniques and methods of evasion. In April 2022, Magniber gained notoriety for disguising itself as a Windows update file to lure victims into installing it. It then began spreading via JavaScript in September 2022.

Detection coverage

  • 3 YARA rules

Detection rules

  • SECUINFRA_RANSOM_Magniber_LNK_Jan23 (yara-rule)
  • CAPE_Magniber (yara-rule)
  • MALPEDIA_Win_Magniber_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Magniber (report)
  • bleepingcomputer.com — Fake Windows 10 Updates Infect You With Magniber Ransomware (report)
  • asec.ahnlab.com — 30645 (report)
  • cybereason.com — Threat Analysis Msi Masquerading As Software Installer (report)
  • bleepingcomputer.com — Magniber Ransomware Gang Now Exploits Internet Explorer Flaws In Attacks (report)
  • CrowdStrike — Magniber Ransomware Caught Using Printnightmare Vulnerability (report)
  • asec.ahnlab.com — 19273 (report)
  • asec.ahnlab.com — 1124 (report)
  • teamt5.org — Internet Explorer The Vulnerability Ridden Browser (report)
  • threatresearch.ext.hp.com — Magniber Ransomware Switches To Javascript Targeting Home Users With Fake Software Updates (report)
  • blog.malwarebytes.com — Magniber Ransomware Exclusively For South Koreans (report)
  • decoded.avast.io — Magnitude Exploit Kit Still Alive And Kicking (report)
  • medium.com — Passive Income Of Cyber Criminals Dissecting Bitcoin Multiplier Scam B9D2B6048372 (report)
  • forensicitguy.github.io — Analyzing Magnitude Magniber Appx (report)
  • asec.ahnlab.com — 41889 (report)
  • decoded.avast.io — Exploit Kits Vs Google Chrome (report)
  • cybereason.com — Threat Analysis Report Printnightmare And Magniber Ransomware (report)
  • Mandiant — Magniber Ransomware Infects Only The Right People (report)
  • blog.google — Magniber Ransomware Actors Used A Variant Of Microsoft Smartscreen Bypass (report)
  • malwarebytes.com — Magniber Ransomware Improves Expands Within Asia (report)
  • youtube.com — Watch (report)
  • therecord.media — Printnightmare Vulnerability Weaponized By Magniber Ransomware Gang (report)
  • hshrzd.wordpress.com — Magniber Ransomware Analysis (report)

External references