SYMBOLCOMMON_NAMEaka. SYNONYMS
win.magniber (Back to overview)

Magniber

VTCollection     URLhaus    

According to TXOne, The Magniber ransomware was first identified in late 2017 when it was discovered using the Magnitude Exploit Kit to conduct malvertising attacks against users in South Korea. However, it has remained active since then, continually updating its tactics by employing new obfuscation techniques and methods of evasion. In April 2022, Magniber gained notoriety for disguising itself as a Windows update file to lure victims into installing it. It then began spreading via JavaScript in September 2022.

References
2023-03-30 ⋅ hasherezade's 1001 nights ⋅ hasherezade
Magniber ransomware analysis: Tiny Tracer in action
Magniber
2023-03-14 ⋅ Google ⋅ Benoit Sevens
Magniber ransomware actors used a variant of Microsoft SmartScreen bypass
Magniber
2022-12-05 ⋅ Cybereason ⋅ Kotaro Ogino, Ralph Villanueva, Robin Plumer
Threat Analysis: MSI - Masquerading as a Software Installer
Magniber Matanbuchus QakBot
2022-11-11 ⋅ AhnLab ⋅ ASEC
Magniber Ransomware Attempts to Bypass MOTW (Mark of the Web)
Magniber
2022-10-13 ⋅ HP ⋅ Patrick Schläpfer
Magniber Ransomware Adopts JavaScript, Targeting Home Users with Fake Software Updates
Magniber
2022-04-30 ⋅ Bleeping Computer ⋅ Lawrence Abrams
Fake Windows 10 updates infect you with Magniber ransomware
Magniber
2022-01-12 ⋅ Avast ⋅ Jan Vojtěšek
Exploit Kits vs. Google Chrome
Magniber UnderminerEK
2022-01-12 ⋅ AhnLab ⋅ ASEC Analysis Team
Magniber Ransomware Being Distributed via Microsoft Edge and Google Chrome
Magniber
2022-01-02 ⋅ forensicitguy ⋅ Tony Lambert
Analyzing a Magnitude EK Appx Package Dropping Magniber
Magniber
2021-11-11 ⋅ Bleeping Computer ⋅ Bill Toulas
Magniber ransomware gang now exploits Internet Explorer flaws in attacks
Magniber
2021-09-22 ⋅ Cybereason ⋅ Aleksandar Milenkoski, Eli Salem
Threat Analysis Report: PrintNightmare and Magniber Ransomware
Magniber
2021-08-12 ⋅ The Record ⋅ Catalin Cimpanu
PrintNightmare vulnerability weaponized by Magniber ransomware gang
Magniber
2021-08-11 ⋅ CrowdStrike ⋅ Liviu Arsene
Teaching an Old Dog New Tricks: 2017 Magniber Ransomware Uses PrintNightmare Vulnerability to Infect Victims in South Korea
Magniber
2021-07-29 ⋅ Avast ⋅ Jan Vojtěšek
Magnitude Exploit Kit: Still Alive and Kicking
Magniber
2021-07-21 ⋅ ⋅ TEAMT5 ⋅ Jason3e7, Peter, Tom
"Le" is not tired of this, IE is really naughty
Magniber
2021-01-13 ⋅ Medium Coinmonks ⋅ Coinmonks, Rakesh Krishnan
Passive Income of Cyber Criminals: Dissecting Bitcoin Multiplier Scam
Magniber
2020-12-22 ⋅ AhnLab ⋅ ASEC Analysis Team
Magniber Ransomware Changed Vulnerability (CVE-2019-1367 -> CVE-2020-0968) and Attempted to Bypass Behavior Detection
Magniber
2018-07-16 ⋅ Malwarebytes Labs ⋅ hasherezade, Jérôme Segura
Magniber ransomware improves, expands within Asia
Magniber
2018-03-30 ⋅ AhnLab ⋅ AhnLab
Magniber
Magniber
2017-12-15 ⋅ hasherezade
Unpacking Magniber ransomware with PE-sieve (former: 'hook_finder')
Magniber
2017-10-19 ⋅ Mandiant ⋅ Muhammad Umair
Magniber Ransomware Wants to Infect Only the Right People
Magniber
2017-10-18 ⋅ Malwarebytes ⋅ Malwarebytes Labs
Magniber ransomware: exclusively for South Koreans
Magniber
Yara Rules
[TLP:WHITE] win_magniber_auto (20260917 | Detects win.magniber.)
rule win_magniber_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.magniber."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.magniber"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 8b4d08 0fb71401 85d2 7507 33c0 }
            // n = 5, score = 400
            //   8b4d08               | mov                 ecx, dword ptr [ebp + 8]
            //   0fb71401             | movzx               edx, word ptr [ecx + eax]
            //   85d2                 | test                edx, edx
            //   7507                 | jne                 9
            //   33c0                 | xor                 eax, eax

        $sequence_1 = { ff15???????? 8b4d08 89816c040000 8b5508 83ba6c040000ff 741a }
            // n = 6, score = 400
            //   ff15????????         |                     
            //   8b4d08               | mov                 ecx, dword ptr [ebp + 8]
            //   89816c040000         | mov                 dword ptr [ecx + 0x46c], eax
            //   8b5508               | mov                 edx, dword ptr [ebp + 8]
            //   83ba6c040000ff       | cmp                 dword ptr [edx + 0x46c], -1
            //   741a                 | je                  0x1c

        $sequence_2 = { ff15???????? 83f810 7411 8d4da8 51 }
            // n = 5, score = 400
            //   ff15????????         |                     
            //   83f810               | cmp                 eax, 0x10
            //   7411                 | je                  0x13
            //   8d4da8               | lea                 ecx, [ebp - 0x58]
            //   51                   | push                ecx

        $sequence_3 = { c78564ffffffb09e4000 c78568ffffffb89e4000 c7856cffffffc09e4000 c78570ffffffc89e4000 c78574ffffffd09e4000 }
            // n = 5, score = 400
            //   c78564ffffffb09e4000     | mov    dword ptr [ebp - 0x9c], 0x409eb0
            //   c78568ffffffb89e4000     | mov    dword ptr [ebp - 0x98], 0x409eb8
            //   c7856cffffffc09e4000     | mov    dword ptr [ebp - 0x94], 0x409ec0
            //   c78570ffffffc89e4000     | mov    dword ptr [ebp - 0x90], 0x409ec8
            //   c78574ffffffd09e4000     | mov    dword ptr [ebp - 0x8c], 0x409ed0

        $sequence_4 = { 51 6a10 8b550c 52 8b45ec }
            // n = 5, score = 400
            //   51                   | push                ecx
            //   6a10                 | push                0x10
            //   8b550c               | mov                 edx, dword ptr [ebp + 0xc]
            //   52                   | push                edx
            //   8b45ec               | mov                 eax, dword ptr [ebp - 0x14]

        $sequence_5 = { 7507 33c0 e9???????? 8d55b8 52 8b45e8 }
            // n = 6, score = 400
            //   7507                 | jne                 9
            //   33c0                 | xor                 eax, eax
            //   e9????????           |                     
            //   8d55b8               | lea                 edx, [ebp - 0x48]
            //   52                   | push                edx
            //   8b45e8               | mov                 eax, dword ptr [ebp - 0x18]

        $sequence_6 = { 83c101 894df8 837df804 0f8dc9000000 }
            // n = 4, score = 400
            //   83c101               | add                 ecx, 1
            //   894df8               | mov                 dword ptr [ebp - 8], ecx
            //   837df804             | cmp                 dword ptr [ebp - 8], 4
            //   0f8dc9000000         | jge                 0xcf

        $sequence_7 = { 52 ff15???????? ebdd 8b45e0 50 6a00 ff15???????? }
            // n = 7, score = 400
            //   52                   | push                edx
            //   ff15????????         |                     
            //   ebdd                 | jmp                 0xffffffdf
            //   8b45e0               | mov                 eax, dword ptr [ebp - 0x20]
            //   50                   | push                eax
            //   6a00                 | push                0
            //   ff15????????         |                     

        $sequence_8 = { 15ce8930e7 9b 283d98b7a0e5 7f9b 0b733e }
            // n = 5, score = 100
            //   15ce8930e7           | enter               -0x2ed4, -0x3a
            //   9b                   | adc                 eax, 0xe73089ce
            //   283d98b7a0e5         | wait                
            //   7f9b                 | sub                 byte ptr [0xe5a0b798], bh
            //   0b733e               | jg                  0xffffff9d

        $sequence_9 = { 56 18cb 52 fc 285f44 }
            // n = 5, score = 100
            //   56                   | push                esi
            //   18cb                 | sbb                 bl, cl
            //   52                   | push                edx
            //   fc                   | cld                 
            //   285f44               | sub                 byte ptr [edi + 0x44], bl

        $sequence_10 = { 7f9b 0b733e fd 6acb 199335632362 }
            // n = 5, score = 100
            //   7f9b                 | loop                0x23
            //   0b733e               | jg                  0xffffff9d
            //   fd                   | or                  esi, dword ptr [ebx + 0x3e]
            //   6acb                 | std                 
            //   199335632362         | push                -0x35

        $sequence_11 = { 8d4f0e 7f4c c82cd1c6 1a32 }
            // n = 4, score = 100
            //   8d4f0e               | lea                 ecx, [edi + 0xe]
            //   7f4c                 | jg                  0x4e
            //   c82cd1c6             | enter               -0x2ed4, -0x3a
            //   1a32                 | sbb                 dh, byte ptr [edx]

        $sequence_12 = { 873428 de9d164df944 ee aa 90 80715bda }
            // n = 6, score = 100
            //   873428               | xchg                dword ptr [eax + ebp], esi
            //   de9d164df944         | ficomp              word ptr [ebp + 0x44f94d16]
            //   ee                   | out                 dx, al
            //   aa                   | stosb               byte ptr es:[edi], al
            //   90                   | nop                 
            //   80715bda             | xor                 byte ptr [ecx + 0x5b], 0xda

        $sequence_13 = { 055457541d e9???????? bc12819787 bbdd81d473 }
            // n = 4, score = 100
            //   055457541d           | add                 eax, 0x1d545754
            //   e9????????           |                     
            //   bc12819787           | mov                 esp, 0x87978112
            //   bbdd81d473           | mov                 ebx, 0x73d481dd

        $sequence_14 = { 32cb 5a b3b1 3e6c }
            // n = 4, score = 100
            //   32cb                 | xor                 cl, bl
            //   5a                   | pop                 edx
            //   b3b1                 | mov                 bl, 0xb1
            //   3e6c                 | insb                byte ptr es:[edi], dx

        $sequence_15 = { 9c 097934 50 5e 5a 3558e9e633 }
            // n = 6, score = 100
            //   9c                   | pushfd              
            //   097934               | or                  dword ptr [ecx + 0x34], edi
            //   50                   | push                eax
            //   5e                   | pop                 esi
            //   5a                   | pop                 edx
            //   3558e9e633           | xor                 eax, 0x33e6e958

    condition:
        7 of them and filesize < 117760
}
Download all Yara Rules