Netskope Threat Labs

Magniber

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Magniber is a ransomware family first identified in late 2017 that used the Magnitude exploit kit to conduct malvertising attacks against users in South Korea. It has remained active for years, and its operators continually refresh its obfuscation and evasion techniques, which included posing as a Windows update file in 2022 and spreading through JavaScript downloads later that year. The family's long run of adaptations shows how a single ransomware brand survives by changing its delivery faster than defenses adjust.

First seen
March 2022
Last seen
October 2026
Alert Name
Gen:Variant.Ransom.Magniber.13
Gen:Variant.Ransom.Magniber.26
Gen:Variant.Ransom.Magniber.28
Generic.Ransom.Magniber.8486CAD0
GT:JS.Magniber.1.01A9B00D
GT:JS.Magniber.1.04F86926
GT:JS.Magniber.1.05029782
GT:JS.Magniber.1.0C2073E0
GT:JS.Magniber.1.0F642546
GT:JS.Magniber.1.1158C541