The Magniber ransomware operation used multiple Windows and Internet Explorer vulnerabilities to compromise victims, with researchers linking the group to attacks that first abused PrintNightmare CVE-2021-34527 and later shifted to browser-based exploitation through CVE-2021-26411 and CVE-2021-40444. CrowdStrike reported Magniber weaponized the remote code execution variant in the Windows Print Spooler service, while subsequent reporting showed the group moving to malvertising-driven infections that delivered ransomware through Internet Explorer flaws. The activity was heavily concentrated in South Korea and broader parts of Asia, matching Magniber’s long-standing regional targeting.
Avast said the group’s Magnitude exploit kit remained active and mature, using adult-site malvertising, victim-specific subdomains, rapidly rotating infrastructure, and polymorphic obfuscation to reach vulnerable Internet Explorer users. The exploit chain also incorporated CVE-2020-0986 for local privilege escalation and sandbox escape before deploying Magniber, which encrypts files, attempts to delete shadow copies, and typically avoids data-theft or double-extortion tactics. Researchers noted the ransomware had been rewritten multiple times, remained effectively uncracked, and in some cases contained flaws that could leave encrypted files unrecoverable even for the attackers.

TTPs, infrastructure, and targeting history in one profile.
15 events from the most recent confirmed update back to the earliest known activity.
ASEC reported that Magniber was being distributed to Microsoft Edge and Google Chrome users through malicious pages offering signed fake browser updates as APPX packages. The report detailed the loader and DLL behavior, in-memory ransomware execution, and published sample hashes and delivery URLs tied to the campaign.
In October 2021, Avast observed the Magnitude exploit kit testing a Chromium exploit chain in the wild that combined CVE-2021-21224 and CVE-2021-31956. The chain ultimately delivered Magniber ransomware, marking a move beyond the kit’s previously documented Internet Explorer-focused activity.
BleepingComputer reported that attackers had exploited Internet Explorer flaw CVE-2021-40444 as a zero-day before Microsoft patched it in September 2021.
CrowdStrike reported that Magniber attacks exploiting CVE-2021-34527 had been occurring since at least July 13, 2021, targeting Windows systems in South Korea.
Microsoft assigned CVE-2021-34527 to the newly distinguished Print Spooler remote code execution flaw and patched it on July 6, 2021, according to The Record.
The Record said researchers published proof-of-concept exploit code for the Print Spooler bug in late June 2021, then removed it within hours after realizing it exposed a different and more severe issue.
BleepingComputer said Microsoft patched the Internet Explorer memory corruption vulnerability CVE-2021-26411 in March 2021.
The Record reported that Magniber has used the Magnitude exploit kit to distribute its payloads since at least 2018.
The Record said Magniber was first spotted in late 2017, and BleepingComputer described it as starting in 2017 as the successor to Cerber ransomware.
Avast said the Magnitude exploit kit has existed since at least 2012 and was originally known as PopAds.
TeamT5 analyzed a Magniber ransomware campaign in which victims browsing with Internet Explorer were redirected through advertising-related sites to malicious doetax[.]site pages that exploited CVE-2020-0968, and in some cases CVE-2021-26411, to deliver ransomware. The researchers also described related abuse of CVE-2019-1367 in forced IE8 compatibility mode to install backdoors instead of ransomware.
BleepingComputer reported that Tencent Security researchers confirmed Magniber was exploiting Internet Explorer vulnerabilities CVE-2021-26411 and CVE-2021-40444 in malvertising-driven ransomware attacks.
Avast analyzed an active adult-malvertising campaign targeting South Korean Internet Explorer users with CVE-2021-26411 and CVE-2020-0986 to deploy Magniber ransomware.
About a week after its initial observation, Avast saw an improved CVE-2020-0986 exploit that delivered Magniber ransomware as the payload.
Avast reported first seeing Magnitude exploit CVE-2020-0986, initially using it only to ping its C2 server with the victim's Windows build number.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
teamt5.org
Open sourceasec.ahnlab.com
Open sourcedecoded.avast.io
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcedecoded.avast.io
Open sourcecrowdstrike.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.