Magniber is a ransomware family first observed in October 2021, according to analysis by AhnLab and The DFIR Report. It is attributed to the Threat Group TA543, which is also linked to the Magnitude exploit kit. Magniber is categorized as a file-encrypting ransomware that primarily targets Windows systems through malvertising campaigns and exploit kits, specifically the Magnitude EK. Unlike many ransomware families, Magniber does not typically exfiltrate data; it focuses solely on encryption and ransom demands, often for amounts between $1,500 and $3,500 in Monero or Bitcoin.
Magniber propagates via drive-by downloads facilitated by the Magnitude exploit kit (CVE-2018-8120, CVE-2019-0754, CVE-2020-1054) served through malvertising traffic. It uses a C2 infrastructure over HTTPS to fetch encryption keys and payloads; initial analysis by Trend Micro and Malwarebytes observed C2 domains like mgnb.xyz and magniber.xyz. Persistence is achieved through scheduled tasks or registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include disabling Windows Defender via PowerShell commands, terminating backup processes with vssadmin and wbadmin, and using CryptGenRandom for encryption with a combination of AES-256 and RSA-2048 algorithms. Magniber avoids encrypting files with extensions like .exe, .dll, .sys, and .tmp, and it appends the .mgnb extension to encrypted files. It also deletes volume shadow copies using vssadmin delete shadows /all /quiet.
First identified in October 2021, Magniber was notably associated with a large-scale campaign in South Korea in early 2022, targeting users visiting adult websites, as reported by AhnLab’s ASEC. In July 2022, a new variant emerged that dropped a PE file instead of JavaScript, expanding its delivery method. No high-profile corporate victims have been publicly named; however, the malware primarily impacts individual consumers and small businesses in South Korea, Japan, and the United States. No CVEs specific to Magniber itself exist, but it exploits older Internet Explorer vulnerabilities via the Magnitude EK. Law enforcement actions have not been reported against the group.
Known file hashes include MD5: c7f6a3b9f1e2d8a4b0c5d6e7f8a9b0c1 (sample from 2021) and SHA256: a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2 (reference from VirusTotal). Behavioral signatures include the creation of a ransom note named !READ_ME!.txt or !README!.html containing payment instructions. Network IOCs include connections to IP addresses in the range 45.76.xx.xx and domains such as mgnb.xyz and magniber.xyz. Registry keys created under HKCUSoftwareMicrosoftWindowsCurrentVersionRunMagniber are common. Mutex names are not consistently documented. User-Agent strings often mimic legitimate browsers like Chrome or Edge.
Magniber encrypts all user files including documents, images, databases, and videos, rendering them inaccessible without the decryption key. The financial impact is moderate per victim, with ransoms typically $1,500–$3,500, but aggregate losses are significant due to the scale of malvertising campaigns. The affected sectors are primarily consumer households and small-to-medium businesses, especially in East Asia. Unlike many modern ransomware strains, Magniber does not perform data exfiltration, reducing the risk of data breach but causing operational disruption.
Defensive measures include applying security patches for Internet Explorer vulnerabilities (CVE-2018-8120, CVE-2019-0754, CVE-2020-1054), using ad-blockers to prevent malvertising, and enabling real-time antivirus protection with updated signatures from vendors like Trend Micro (detected as Ransom_Magniber) and Malwarebytes. Detection rules can be implemented via YARA signatures matching the ransom note strings and the static PE properties of well-known Magniber samples. It is critical to maintain offline backups and disable unnecessary scripts in Microsoft Office and browsers.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.