Magniber — Ransomware Profile
Magniber is a Windows ransomware family first documented by Trend Micro in October 2017, when the Magnitude exploit kit dropped its usual Cerber payload in favour of this previously unseen malware. Early builds were unusually narrow: the malware inspected the installed system language and only fully executed on machines whose locale identifier was 0x0412, the identifier for Korean, and Trend Micro records it as exclusively targeting South Korea in 2017. From 2018 the operators widened their reach across Asia using CVE-2018-8174 for initial access, and Trend Micro later reported the targeting expanding beyond Asian countries; the malware was also observed posing as fake installers and Windows updates to lure users into running the payload. The crew repeatedly built campaigns on Microsoft flaws: the Magnitude kit carrying it weaponised CVE-2016-0189, CVE-2018-8174 and CVE-2019-1367, later activity used the MSHTML remote-code-execution bug CVE-2021-40444, and Google's Threat Analysis Group tied Magniber to the Windows SmartScreen bypass CVE-2022-44698 and then to a variant of it patched as CVE-2023-24880 — in that 2023 campaign TAG observed more than 100,000 downloads of malicious MSI files since January 2023, over 80% of them to users in Europe, a notable divergence from Magniber's usual South Korea and Taiwan focus. AhnLab's ASEC reported that distribution halted as of 25 August 2023, and its May 2026 ransomware reporting still attributes the decline in detections since then to that suspension, so the family is best treated as dormant even though residual infections were still being detected at roughly 30 systems a day in January 2025, with no new variants or redistributions.
Vendor research
Read the full analysis on IntelFusions