Magnitude Exploit Kit is a long-running web-based exploit kit active since at least 2013 and notable for sustained use well after the broader exploit-kit ecosystem declined. It is primarily associated with drive-by compromise through malvertising and redirector infrastructure, including the Magnigate filtering gate, to profile victims and deliver browser-based exploitation chains. The kit has been observed targeting Internet Explorer extensively and, in 2021, briefly testing a Chromium exploit chain in the wild.
Magnitude is best known for delivering ransomware payloads, especially Magniber, and previously delivered other ransomware families including Cerber and GandCrab. Its campaigns were historically concentrated on South Korea and later expanded to parts of the Asia-Pacific region including Taiwan, Hong Kong, and Malaysia. Regional targeting and victim filtering have been a recurring operational characteristic.
Observed exploitation by Magnitude has included Internet Explorer vulnerabilities such as CVE-2018-8174 and CVE-2021-26411, as well as a Chromium chain using CVE-2021-21224 for renderer code execution and CVE-2021-31956 for Windows kernel privilege escalation. In documented chains, successful browser exploitation led to shellcode execution, staged payload retrieval, and delivery of a loader that injected the final ransomware payload into a running process. The Chromium chain demonstrated mature post-exploitation tradecraft, including sandbox escape, SYSTEM token theft, process injection, and cleanup steps intended to avoid system instability.
Magnitude remains one of the most prominent surviving exploit kits of its era and has been closely linked to Magniber operations since at least 2017. Its role is primarily as an exploitation and delivery platform rather than the final payload itself, enabling initial access and follow-on malware execution on Windows systems through browser-driven drive-by attacks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Magnitude exploit kit is one of the longest-serving browser exploitation toolkits among those still in use.
The Magnitude exploit kit is one of the longest-serving browser exploitation toolkits among those still in use.
In October 2021, we discovered that the Magnitude exploit kit was testing out a Chromium exploit chain in the wild.
In October 2021, we discovered that the Magnitude exploit kit was testing out a Chromium exploit chain in the wild.
In October 2021, we discovered that the Magnitude exploit kit was testing out a Chromium exploit chain in the wild.
In October 2021, we discovered that the Magnitude exploit kit was testing out a Chromium exploit chain in the wild.
In October 2021, we discovered that the Magnitude exploit kit was testing out a Chromium exploit chain in the wild.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
The document repeatedly lists exploit kits alongside client-side CVEs such as CVE-2013-2551, CVE-2013-0634, CVE-2013-0422, CVE-2012-0507, CVE-2011-3544, CVE-2010-0188, and many others affecting Java, Flash, Internet Explorer, Adobe Reader, QuickTime, and Windows Media Player.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Browser exploit kit used in drive-by malvertising attacks. In this content, it weaponizes a Chromium renderer exploit (CVE-2021-21224) chained with a Windows kernel sandbox escape/LPE (CVE-2021-31956), then deploys Magniber ransomware.
Web-based exploit kit used to distribute Magniber payloads by exploiting browser vulnerabilities.
Long-running exploit kit active in limited geographies such as South Korea and Taiwan, used in drive-by download attacks and continuing to evolve.
Exploit kit cited as active in Russian underground trade.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.