mag-net
Mag-Net is a malicious web vulnerability scanner and automated attack bot first identified in 2019 by security researchers at Imperva and Sucuri. Its exact origin and maintainer remain unconfirmed, but analysis of its User-Agent strings and IP distribution suggests it is operated by a Chinese-language threat actor group focused on mass exploitation of e-commerce and content management systems.
Mag-Net primarily performs automated recon for SQL injection, cross-site scripting (XSS), and remote file inclusion (RFI) vulnerabilities, targeting platforms such as Magento, WordPress, Joomla, and Drupal. It sends concurrent requests from hundreds of IP addresses, often using randomized User-Agent strings to evade basic detection. The bot probes for known CMS-specific endpoints, such as /wp-admin/admin-ajax.php and /index.php?option=com_users, and attempts blind SQL injection via parameter pollution. Once a vulnerable endpoint is found, Mag-Net can exfiltrate database contents, escalate privileges, or drop webshells for persistent access. Traffic analysis shows it maintains low request rates per IP (2–5 requests per minute) to avoid rate limiting, while rotating through a pool of thousands of residential proxies.
First documented in a Sucuri blog post (March 2020) under the title “Mag-Net Bot: A New Mass Scanner on the Rise,” the bot was linked to a series of attacks against Magento 1.x stores exploiting the SUPEE-8788 vulnerability (CVE-2016-4010). In late 2021, Imperva’s Threat Research team reported that Mag-Net accounted for 12% of all SQLi scan traffic observed across their network, primarily targeting U.S. and European e-commerce sites. No specific corporate breach has been publicly attributed solely to this bot, but its consistent activity correlates with multiple unpatched Magento compromise waves in 2022–2023.
The primary detection indicator is the User-Agent string “Mozilla/5.0 (compatible; Mag-Net/1.0; +http://www.mag-net.com/)”, though variants like “Mag-Net/2.0” or “Mag-Net-Web-Scanner” have been observed. Behavioral fingerprints include sequential probing of common CMS paths (e.g., /wp-content/plugins/ followed by /skin/frontend/) within a 30-second window, combined with HTTP headers that omit the Accept-Encoding field. Traffic from a single IP rarely exceeds 50 total requests before switching, and the bot frequently uses HTTP/1.0 instead of HTTP/1.1.
Successful exploitation enables full database theft, credential harvesting, and backend server takeover. Attackers can leverage Mag-Net to install cryptocurrency miners, deface websites, or pivot to internal networks, potentially causing regulatory fines under GDPR or PCI DSS. Even unsuccessful scans degrade server performance and increase operational costs through wasted bandwidth and logging.
Mag-Net is blocked immediately on detection because its sole purpose is automated vulnerability discovery and exploitation, with no legitimate use case. Firewall rules should drop traffic matching the known User-Agent patterns, and WAFs should inspect for SQLi/XSS payloads in query strings from IP ranges associated with residential proxy services.
Similar Threats
⚠️
Unwanted bots inflate your analytics, drain server resources, and slow down real users. Check if your site is affected — completely free.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.