Magnet Goblin is a financially motivated cybercriminal threat actor that rapidly exploits newly disclosed vulnerabilities in internet-facing services and edge devices to deploy custom malware. Its activity dates to at least 2022 and includes campaigns against Magento, Qlik Sense, and Ivanti Connect Secure. The group adopted exploitation of Ivanti vulnerability CVE-2024-21887 within approximately one day of a public proof of concept becoming available. Its campaigns have also exploited Magento vulnerability CVE-2022-24086 and Qlik Sense vulnerabilities CVE-2023-41265, CVE-2023-41266, and CVE-2023-48365. Magnet Goblin's arsenal includes Linux variants of NerbianRAT, the simplified Linux backdoor MiniNerbian, and a customized WARPWIRE JavaScript credential stealer. NerbianRAT and MiniNerbian provide remote command execution, command-result retrieval, configurable communication intervals, and scheduled activity. NerbianRAT also collects basic host information and encrypts command-and-control communications. In its Ivanti campaigns, the group deployed WARPWIRE to steal VPN credentials and Ligolo for tunneling. It also uses legitimate remote-access software, including ScreenConnect and AnyDesk. Compromised Magento servers have served as command-and-control infrastructure for subsequent operations. Its deployment of custom Linux backdoors on edge devices helps reduce visibility into its activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
Magento – CVE-2022-24086
At least in one case of Ivanti Connect Secure VPN (CVE-2024-21887), the exploit entered the group’s arsenal as fast as within 1 day after a POC for it was published.
Qlik Sense – CVE-2023-41265, CVE-2023-41266, and CVE-2023-48365
Qlik Sense – CVE-2023-41265, CVE-2023-41266, and CVE-2023-48365
Ivanti Connect Secure – CVE-2023-46805 and CVE-2024-21887, CVE-2024-21888 and CVE-2024-21893.
3 more CVEs tied to this actor tracked in Mallory.
41 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a cybercrime crew noted for exploiting Ivanti vulnerabilities.
Magnet Goblin is an economically motivated threat actor exploiting 1-day vulnerabilities in public-facing servers to deploy custom malware on Windows and Linux systems.
Referenced as a cybercrime crew newly observed exploiting Ivanti vulnerabilities ("Ivanti holes"). No additional operational details, tooling, or targeting information is provided in this content.
Financially motivated actor exploiting recently disclosed vulnerabilities in internet-facing services to deploy Linux backdoors and steal VPN credentials. Attributed campaigns target Ivanti Connect Secure, Magento, and Qlik Sense; Apache ActiveMQ exploitation is suspected. Its arsenal includes Linux and Windows NerbianRAT variants, MiniNerbian, WARPWIRE, tunneling tools, and legitimate remote-management software. The reported connection to Cactus is unverified.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.