Magniber is a ransomware operation first observed in 2017 and widely regarded as the successor to Cerber in that lineage. It has historically concentrated on victims in Asia, especially South Korea, and later expanded targeting to China, Taiwan, Hong Kong, Singapore, and Malaysia. Reporting has repeatedly characterized its activity as geographically focused on Asian organizations rather than broad global victimization. The group is notable for aggressive exploitation of Windows and browser-related vulnerabilities for initial access and ransomware deployment. Magniber has been observed weaponizing PrintNightmare, including CVE-2021-34527, against Windows systems in South Korea. It has also used Internet Explorer vulnerabilities including CVE-2021-26411 and CVE-2021-40444 in malvertising-driven campaigns, and later exploited Mark-of-the-Web bypass vulnerabilities such as CVE-2022-41091 and CVE-2022-44698 to suppress security warnings and facilitate execution of malicious payloads. Fake software updates, phishing-delivered JavaScript, exploit-kit delivery, and malicious advertisements have all been associated with Magniber intrusion chains. Magniber has long been associated with exploit-kit-based delivery, including use of Magnitude, and with practical defense-evasion tradecraft centered on bypassing Windows trust and warning mechanisms. The malware has reportedly been rewritten multiple times since launch, indicating sustained development and operational maintenance. Unlike many modern ransomware groups, Magniber has been described as focusing on file encryption rather than data theft or double extortion, and no reliable public decryptor was available at the time of the cited reporting. Aliases include Magniber and Magniber ransomware group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation referenced as previously using malvertising as a distribution/initial access vector.
Referenced as another campaign exploiting the same Windows Mark of the Web zero-day bypass using signed malicious JavaScript files to deliver ransomware.
Weaponized a Windows Mark-of-the-Web (MoTW) security feature bypass (CVE-2022-41091) to deliver ransomware via fake software update lures.
Observed exploiting a Windows Mark-of-the-Web (MoTW) security feature bypass (CVE-2022-41091) in the wild to facilitate ransomware activity, likely relying on user interaction to open a crafted file that bypasses Protected View/MoTW protections.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.