Magniber is a Windows ransomware family first observed in 2017 and long associated with exploit-driven and socially engineered delivery. It has been distributed through the Magnitude exploit kit, malicious advertisements, fake browser or Windows updates, typosquatted download sites, signed script files, MSI installers, APPX packages, and phishing-delivered JavaScript. Multiple campaigns abused Internet Explorer and Windows vulnerabilities including CVE-2018-8174, CVE-2019-1367, CVE-2020-0968, CVE-2021-26411, CVE-2021-40444, CVE-2021-34527, and the SmartScreen bypass CVE-2022-44698 to execute without normal user warnings or to gain code execution on vulnerable systems.
Magniber primarily targets Windows systems and has historically shown strong concentration in South Korea, later expanding to other parts of Asia including Taiwan, Hong Kong, Malaysia, Singapore, and Chinese-language locales. Some campaigns also spread more broadly to consumer victims worldwide through fake software-update lures. The malware encrypts files and drops ransom notes, while many reports note that it generally focused on encryption rather than data theft or double-extortion operations.
Technically, Magniber has undergone repeated rewrites and operational changes to improve evasion and resilience. Reported variants use obfuscation, dynamic API resolution, malformed or corrupted Authenticode signatures to bypass Mark-of-the-Web and SmartScreen protections, reflective DLL loading, and process injection to run inside legitimate processes. Some campaigns used shellcode loaders, in-memory execution, MSI custom actions, APPX-based staging, and Heaven’s Gate techniques to reduce visibility to user-mode security tooling. Magniber operators also changed injection sequences over time to evade behavior-based detection and have used privilege-escalation or exploit chains in conjunction with browser-based delivery.
Encryption behavior documented across campaigns includes AES-based file encryption with per-file keys and IVs, with the symmetric material protected using RSA and appended to encrypted files. Later variants no longer depended on a command-and-control server or hardcoded online key retrieval for encryption, instead embedding attacker-controlled public-key material locally. Magniber has also been observed deleting shadow copies and otherwise hindering recovery.
Magniber has been linked in reporting to cybercriminal activity tracked by Microsoft as Storm-0381, and its ecosystem has intersected with exploit suppliers and malvertising operations. It remains notable for sustained adaptation in delivery and defense evasion, especially its repeated use of browser and Windows trust-boundary weaknesses to reach victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The operators of the Magniber ransomware have weaponized the infamous PrintNightmare vulnerability and are now attempting to breach Windows systems in South Korea.
The Magniber ransomware gang is now using two Internet Explorer vulnerabilities and malicious advertisements to infect users and encrypt their devices... The second flaw, CVE-2021-40444, is a remote code execution in IE’s rendering engine triggered by the opening of a malicious document. Attackers exploited CVE-2021-40444 as a zero-day before Microsoft fixed it in September 2021. | The Magniber ransomware gang is now using two Internet Explorer vulnerabilities and malicious advertisements to infect users and encrypt their devices.
In our recent captures of Magnitude, we now see the latest Internet Explorer exploit (CVE-2018-8174) being used primarily... After CVE-2018-8174’s exploitation, the XOR-encrypted Magniber is retrieved... Once exploitation of the Use After Free vulnerability in Internet Explorer (CVE-2018-8174) is successful, the VBScript will execute the following shellcode. | In this post, we take a look at some notable changes with Magniber. Its source code is now more refined, leveraging various obfuscation techniques and no longer dependent on a Command and Control server or hardcoded key for its encryption routine.
The Magniber ransomware gang is now using two Internet Explorer vulnerabilities and malicious advertisements to infect users and encrypt their devices. The two Internet Explorer vulnerabilities are tracked as CVE-2021-26411 and CVE-2021-40444... The first one, CVE-2021-26411, was fixed in March 2021 and is a memory corruption flaw triggered by viewing a specially crafted website. | The Magniber ransomware gang is now using two Internet Explorer vulnerabilities and malicious advertisements to infect users and encrypt their devices.
Magnitude using CVE-2021-21224 and CVE-2021-31956 ... This is an exploit for CVE-2021-31956, a paged pool buffer overflow in the Windows kernel ... The first one contains an exploit for CVE-2021-31956. This one gets executed first and its goal is to steal the SYSTEM token to elevate the privileges of the current process.
CVE-2018-8641* Classification: 1-Day Basic Description: Double Free in win32k!xxxTrackPopupMenuEx ... Found in the following Malware samples: Magniber | Found in the following Malware samples: Magniber
Magnitude using CVE-2021-21224 and CVE-2021-31956 ... The exploitation starts with a JavaScript exploit for CVE-2021-21224. This is a type confusion vulnerability in V8, which allows the attacker to execute arbitrary code within a (sandboxed) Chromium renderer process.
In response, the developer changed the latest vulnerability to CVE-2020-0968, expanding the infection target range. On top of this occurrence, CVE-2020-0968 security patch (distributed on April 15, 2020) cannot be applied to Windows 7 as it is no longer supported as of January 14, 2020. | the developer of Magniber used for distribution, stopped operating in the systems with emergency security patch (Version 1903) applied. In response, the developer changed the latest vulnerability to CVE-2020-0968, expanding the infection target range.
Since September 23, 2019, CVE-2019-1367 vulnerability, which the developer of Magniber used for distribution, stopped operating in the systems with emergency security patch (Version 1903) applied. | the developer of Magniber used for distribution, stopped operating in the systems with emergency security patch (Version 1903) applied. In response, the developer changed the latest vulnerability to CVE-2020-0968, expanding the infection target range.
Microsoft patched the security bypass in December 2022 as CVE-2022-44698. Similar to the bypass occurring now, Magniber ransomware actors used CVE-2022-44698 before a patch was made available. | In September 2022, Magniber ransomware was delivered using JScript files... Similar to the bypass occurring now, Magniber ransomware actors used CVE-2022-44698 before a patch was made available. However, the Magniber actors used JScript files during the previous campaigns, whereas in the current campaign they are using MSI files with a different type of malformed signature.
Magnitude currently exploits... a Windows memory corruption vulnerability, CVE-2020-0986, to subsequently elevate privileges... Magnitude escapes the EPM sandbox by exploiting CVE-2020-0986, a memory corruption vulnerability in splwow64.exe.
Both vulnerabilities are remote code execution flaws (RCE) and have since been exploited in the wild by ransomware groups like Magniber and Vice Society.
Researchers at HP observed the Magniber ransomware group exploiting this vulnerability in the wild.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Microsoft identified Magniber deployments from the Russian cybercrime group that it tracks as Storm-0381 through its heavy use of malvertising.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
After Magnigate’s 302 redirection (Step 1), we see a Base64 obfuscated JavaScript (Step 2) used to launch Magnitude’s landing page, along with a Base64 encoded VBScript.
we see a Base64 obfuscated JavaScript (Step 2) used to launch Magnitude’s landing page, along with a Base64 encoded VBScript... the VBScript will execute the following shellcode
the threat operator used scripts as the distribution method during the period from September 8th to September 29th, 2022.
ZwCreateSection -> ZwMapViewOfSection ... ZwCreateThreadEx ... NtCreateSection -> NtMapViewOfSection ... NtCreateThreadEx | Instead of calling NtOpenProcess API in a normal way, Magniber shellcode sends SysCall index (0x23) directly to argument and calls fs:[C0] area... Because Magniber shellcode uses Heaven’s Gate technique to call 64-bit API directly from the 32-bit process (Internet Explorer), it is difficult to detect API call via common hooking.
The exploitation starts with a JavaScript exploit for CVE-2021-21224. This is a type confusion vulnerability in V8, which allows the attacker to execute arbitrary code within a (sandboxed) Chromium renderer process.
This loader unpacks the Magniber’s core DLL... and injects it into a process. Both elements, the loader and Magniber core, are DLLs with Reflective Loader stub... using the Reflective DLL injection technique.
OpenProcess -> WriteProcessMemory -> SetThreadContext -> ResumeThread ... NtCreateThreadEx -> GetThreadContext -> SetThreadContext -> NtResumeThread
we managed to track down more than 10 (!) of their Windows Kernel Local Privilege Escalation (LPE) exploits, many of which were zero-days at the time of development.
Its source code is now more refined, leveraging various obfuscation techniques... After Magnigate’s 302 redirection (Step 1), we see a Base64 obfuscated JavaScript... the XOR-encrypted Magniber is retrieved.
First of all, API functions are now dynamically retrieved by their checksums... The function pointer is retrieved by searching through export tables of the DLLs that are currently loaded.
Both pages prompt users to install Windows application package file (.appx) to update the corresponding browser... the APPX file disguised as Chrome or Edge’s Windows update application internally contains a valid certificate.
This loader unpacks the Magniber’s core DLL... and injects it into a process. Both elements, the loader and Magniber core, are DLLs with Reflective Loader stub... using the Reflective DLL injection technique.
OpenProcess -> WriteProcessMemory -> SetThreadContext -> ResumeThread ... NtCreateThreadEx -> GetThreadContext -> SetThreadContext -> NtResumeThread
Figure 6 is a part of the DLL code that downloads the ransomware’s encoded payload and decodes it.
Modifies reference registry upon execution of fodhelper.exe (HKCU:\Software\Classes\ ms-settings \shell\open\command)
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family described as capable of running code inside another process to make disruption and detection harder.
Ransomware whose distribution suspension was linked to a decline in detections.
A ransomware family mentioned as one of the payloads delivered by Magnitude Exploit Kit.
Ransomware delivered via Internet Explorer exploit chains. The sample analyzed encrypts files with AES-CBC and then encrypts the AES key and IV with RSA, appending the encrypted blob to the end of each encrypted file.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.