Magnat is the name associated with a long-running financially motivated malware distribution operation active since at least 2018. The actor is linked to fake installers for popular software that deliver a recurring payload set centered on credential theft and monetization of compromised access. The campaign has been associated with a commodity stealer that evolved over time from Azorult to RedLine Stealer, alongside two custom malware families commonly referred to as MagnatBackdoor and MagnatExtension. The operation has primarily targeted users in Canada, with additional victimization observed in the United States, Australia, Italy, Spain, Norway, and other European countries. Infection chains have been tied to deceptive software-download lures and likely malvertising aimed at users searching for legitimate applications. MagnatBackdoor is an AutoIt-based backdoor focused on enabling covert remote desktop access. It prepares infected systems for remote use by creating a user account, modifying local permissions and firewall settings, enabling Remote Desktop, establishing persistence through scheduled tasks, and supporting outbound tunneling for remote access. This indicates a strong emphasis on post-compromise access resale or direct operator use of infected hosts. MagnatExtension is a malicious browser extension that functions similarly to a banking trojan and browser surveillance platform. Its capabilities include form grabbing, keylogging, screenshot capture, cookie theft, browsing history collection, and execution of arbitrary JavaScript in browser tabs under command-and-control direction. It has also been used to manipulate page content in the browser while preserving the visible destination context, supporting theft of credentials, session material, and financial account information. Observed targeting included social media, online payment services, and cryptocurrency-related web activity. Across observed campaigns, Magnat has demonstrated iterative malware development, testing of replacement stealers, use of obfuscated AutoIt loaders, in-memory payload decoding, and process injection. The actor is best characterized as a financially motivated cybercriminal operator focused on credential theft, session theft, fraudulent transactions, and monetization of remote access to compromised systems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
107 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.