The Magnitude exploit kit remained active and under active development, continuing to deliver ransomware through malvertising to users in Asia-Pacific countries despite the broader decline of exploit kits. Over a 12-month period, researchers observed frequent changes to its shellcode, payload delivery, process injection techniques, and anti-analysis logic, indicating sustained operator investment and adaptation.
In early 2020, the kit moved from exploiting CVE-2018-8174 to CVE-2019-1367, a Microsoft Internet Explorer flaw in the legacy JScript engine, and also used a previously unknown elevation-of-privilege exploit for CVE-2018-8641 in win32k. The delivered ransomware used Microsoft CryptoAPI to encrypt files, dropped ransom notes, and attempted to delete shadow copies through a UAC bypass, reinforcing that unpatched Internet Explorer systems remained exposed to a mature exploit-to-ransomware infection chain.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
On March 16, 2020, the exploit kit added logic to avoid injecting its payload into explorer.exe, reflecting another change in its process injection behavior.
Also on February 11, 2020, Magnitude EK added logic to check for the ASDSvc process associated with AhnLab and avoid executing the payload from Internet Explorer if that process was present.
On February 11, 2020, Magnitude EK changed its primary browser exploit from CVE-2018-8174 to CVE-2019-1367, reusing the original Internet Explorer zero-day exploit with modified shellcode and obfuscation.
During 2019, Magnitude EK used CVE-2018-8174 as its exploit, matching a broader pattern seen across other exploit kits at the time.
The article says the win32k elevation-of-privilege vulnerability CVE-2018-8641 used by Magnitude EK was fixed by Microsoft in December 2018.
The Securelist analysis states that Magnitude exploit kit has existed since at least 2013 and was originally advertised on underground forums before later becoming a private exploit kit.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.