Magnitude Exploit Kit is a long-running exploit kit and malvertising operation active since at least the early 2010s, best known for targeting Internet Explorer users in Asia-Pacific, especially South Korea, and for delivering ransomware payloads such as Magniber and earlier families including Cerber, Locky, CryptoWall, and GandCrab. It has been associated with opportunistic web-based compromise through malicious advertising chains and exploit landing pages, with campaigns frequently tailored to specific geographies, browser versions, and Windows builds.
Magnitude commonly uses malvertising and redirect chains to drive victims to exploit infrastructure, where browser-based code execution vulnerabilities in Internet Explorer are used to gain execution. Reported campaigns have exploited vulnerabilities including CVE-2019-1367 and CVE-2021-26411, and later stages have used Windows privilege-escalation vulnerabilities such as CVE-2020-0986 to escape browser sandboxes and elevate execution before deploying final payloads. Operations have used rapidly rotating infrastructure, victim-specific subdomains, and polymorphic JavaScript obfuscation to hinder detection and takedown.
The kit has been described as highly selective in targeting, with campaigns focused on South Korean Internet Explorer users and, at times, other Asia-Pacific countries including Taiwan and Japan. Distribution has included adult-themed malvertising and fake update lures, and later activity also included social-engineering delivery of Magniber through signed application packages. In observed chains, Magnitude has performed staged payload retrieval and process injection to launch ransomware in another process.
Magnitude is most notable as a delivery platform rather than as a payload family itself. Its core role is to provide initial access and execution for follow-on malware, especially ransomware. In later campaigns delivering Magniber, the overall intrusion chain included local privilege escalation, payload staging, and deployment of ransomware that encrypted files, dropped ransom notes, and in some cases exfiltrated limited deployment metadata. Magnitude remains one of the few exploit kits that continued meaningful in-the-wild activity after the broader decline of the exploit-kit ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Magnitude Exploit KIT : An opportunistic Malvertiser, mostly targeting south Korea. Magnitude EK has been there since 2013, and known to drop very known ransomware families including: Locky, Cerber, Magniber, CryptoWall, GranCrab..
The first case study is CVE-2015-2419, a double-free in jscript9 and this particular vulnerability is being exploited in most of the popular exploit kits. This specific example depicted below was taken from the Magnitude exploit kit.
The attackers behind the Magnitude Exploit Kit (or Magniťůdek as we like to call it) are exploiting this momentum by running malicious ads that are currently shown only to South Korean Internet Explorer users. | Magnitude currently exploits... a Windows memory corruption vulnerability, CVE-2020-0986, to subsequently elevate privileges... Magnitude escapes the EPM sandbox by exploiting CVE-2020-0986, a memory corruption vulnerability in splwow64.exe.
The attackers behind the Magnitude Exploit Kit (or Magniťůdek as we like to call it) are exploiting this momentum by running malicious ads that are currently shown only to South Korean Internet Explorer users. | Magnitude currently exploits an Internet Explorer memory corruption vulnerability, CVE-2021-26411, to get shellcode execution inside the renderer process... A fully functional exploit for CVE-2021-26411 can be found on the Internet and Magnitude uses that public exploit directly, just with some added obfuscation on top.
Being asked for the CVE he wrotes : CVE-2012-0507 CVE-2013-2551 CVE-2013-2471
Flash exploit was only a downloader, (not CVE-2013-0634)
and no more CVE-2011-3402 (Duqu Like Font Drop)
Being asked for the CVE he wrotes : CVE-2012-0507 CVE-2013-2551 CVE-2013-2471
Being asked for the CVE he wrotes : CVE-2012-0507 CVE-2013-2551 CVE-2013-2471
Rintaro and Hajime gave an update on an exploit kit called Magnitude Exploit Kit observed in 2021 and the analysis results of ransomware called Magniber, which is executed by this kit.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers behind the Magnitude Exploit Kit are exploiting this momentum by running malicious ads that are currently shown only to South Korean Internet Explorer users. The ads can mostly be found on adult websites, which makes this an example of so-called adult malvertising.
The command that Magnitude executes in the call to system looks like this: icacls <dropped_64bit_PE> /Q /C /setintegritylevel Medium && <dropped_64bit_PE>
returning Jscript encoded data... After decoding, we are greeted with the full CVE-2019–1367 exploit, but obfuscated
Once a suitable target process is found, the shellcode jumps through the Heaven’s Gate and injects the payload into the target process using the following sequence of syscalls: NtOpenProcess -> NtCreateSection -> NtMapViewOfSection -> NtCreateThreadEx -> NtGetContextThread -> NtSetContextThread -> NtResumeThread.
base64 only data is returned, typical to Magnitude Exploit KIT landing page... returning Jscript encoded data... After decoding, we are greeted with the full CVE-2019–1367 exploit, but obfuscated
Once a suitable target process is found, the shellcode jumps through the Heaven’s Gate and injects the payload into the target process using the following sequence of syscalls: NtOpenProcess -> NtCreateSection -> NtMapViewOfSection -> NtCreateThreadEx -> NtGetContextThread -> NtSetContextThread -> NtResumeThread.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An exploit kit used in malvertising campaigns, noted for rapidly integrating new CVEs and delivering follow-on payloads including ransomware.
Exploit kit observed in Japan (noted since ~Oct 2021) used to deliver Magniber; features include exploiting new vulns (e.g., CVE-2021-40444) and social-engineering-based distribution.
A long-running exploit kit used in malvertising campaigns, particularly against Internet Explorer users, to exploit CVE-2021-26411 and CVE-2020-0986 and deliver payloads in memory. In the described campaign it delivers Magniber ransomware.
Actively maintained exploit kit targeting Internet Explorer vulnerabilities and delivering ransomware in APAC via malvertising; noted use of CVE-2019-1367 and an EoP exploit for CVE-2018-8641.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.