Magnet Goblin is a financially motivated cybercrime threat actor known for rapidly exploiting recently disclosed 1-day vulnerabilities in internet-facing enterprise software to compromise public-facing servers. The group has been associated with exploitation of products including Ivanti, Apache ActiveMQ, and Qlik Sense, followed by deployment of custom malware on both Windows and Linux systems. Reported tooling includes the malware families NerbianRAT and MiniNerbian. The actor’s tradecraft emphasizes opportunistic initial access through vulnerability exploitation rather than long-dwell intrusion sets. Its operations have been characterized by fast weaponization of newly available exploits against exposed services, suggesting strong reconnaissance and scanning capability focused on identifying vulnerable edge infrastructure. Post-compromise activity includes malware deployment and broader post-exploitation actions consistent with establishing control over compromised hosts. Magnet Goblin is tracked as a cybercriminal rather than a state-sponsored espionage actor. Available reporting supports financial gain as its dominant motivation. No high-confidence evidence in the supplied facts directly ties the group to ransomware deployment, extortion operations, or a specific country of origin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Magnet Goblin 利用这些缺陷使用自定义恶意软件(特别是 NerbianRAT 和 MiniNerbian)以及 WARPWIRE JavaScript 窃取程序的自定义变体来感染服务器。
黑客组织Magnet Goblin于公开披露漏洞后的第二天就部署了一天的漏洞利用。在近几个月曝光的五个漏洞中,CVE-2024-21887 最为突出。 Ivanti Connect Secure 和 Policy Secure 网关中的命令注入漏洞在 CVSS 评分中被评为“严重”9.1 级(满分 10 分)。
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a cybercrime crew noted for exploiting Ivanti vulnerabilities.
Magnet Goblin is an economically motivated threat actor exploiting 1-day vulnerabilities in public-facing servers to deploy custom malware on Windows and Linux systems.
Referenced as a cybercrime crew newly observed exploiting Ivanti vulnerabilities ("Ivanti holes"). No additional operational details, tooling, or targeting information is provided in this content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.