Skip to content

Magniber

Magniber is a ransomware family commonly known as Magniber and closely associated with the Magnitude Exploit Kit, which has distributed it since 2017 as a replacement for Cerber.

Profile source: Mallory opens in a new tab

Magniber

Family profile

Magniber is a ransomware family commonly known as Magniber and closely associated with the Magnitude Exploit Kit, which has distributed it since 2017 as a replacement for Cerber. Reported delivery vectors in the provided content include adult-themed malvertising campaigns targeting vulnerable Microsoft Windows and Internet Explorer users, exploitation of Internet Explorer and Windows vulnerabilities such as CVE-2021-26411 and CVE-2020-0986, exploitation of CVE-2019-1367 by Magnitude EK, fake software updates, and a signed AppX package masquerading as a Microsoft Edge update. The content also states that Magniber actors exploited Windows Mark-of-the-Web bypass CVE-2022-41091 and separately exploited CVE-2022-44698, and that ransomware groups including Magniber exploited Windows Print Spooler flaws CVE-2021-1675 and CVE-2021-34527 in the wild.

Behaviorally, Magniber enumerates logical drives, recursively encrypts selected file types, excludes certain folders and hidden, system, readonly, temporary, and virtual files, and drops ransom notes in affected folders as well as an additional note in %PUBLIC%, which it opens with notepad.exe. The current version described in the content generates per-file AES-128 keys and IVs locally using a custom PRNG and encrypts them with an embedded RSA public key. It also opens a victim-specific payment page and exfiltrates deployment metadata including encrypted-file counts, total encrypted size, encrypted-drive counts, total encountered files, Windows version, victim identifier, and Magniber version. It attempts to delete shadow copies using UAC bypass techniques involving CompMgmtLauncher.exe on older systems and ComputerDefaults.exe plus DelegateExecute on Windows 10. One reported bug affects files whose size is a multiple of 0x100000 bytes, potentially making them unrecoverable even for the attackers.

The content links Magniber strongly to South Korea and, at times, Taiwan and Japan, while earlier Magnitude campaigns also targeted Hong Kong, Singapore, the United States, and Malaysia. It is described as one of the most prevalent ransomware families in some telemetry, accounting for 62% of detected ransomware cases in one Q4 2024 report. Additional sample analysis in the content describes a Magniber-linked AppX package containing a .NET executable and an obfuscated DLL using manual syscalls, jump-heavy control flow, and behavior consistent with memory allocation and possible unpacking or injection. Indicators explicitly provided in the content include the AppX sample edge_update.appx; executable eediwjus.exe with SHA-256 ad4f74c0c3ac37e6f1cf600a96ae203c38341d263dbac0741e602686794c4f5a; DLL eediwjus.dll with SHA-256 f423bd6daae6c8002acf5c203267e015f7beb4c52ed54a78789dd86ab35e46c6; and Magnitude-related infrastructure examples such as binlo[.]info, fab9z1g6f74k.tooharm[.]xyz, 6za16cb90r370m4u1ez.burytie[.]top, bluegas[.]website, and pophot[.]website.

Operational record

1
YARA rules
1
Leak sites
0 available

Exploited software

Vulnerabilities linked to Magniber

8 CVEs

MITRE ATT&CK

Magniber in ATT&CK

15 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.