Friday, April 18, 2025
HomeRansomwareMagniber Ransomware Improves Its Obfuscation Techniques and Expands to Other Asian Countries

Magniber Ransomware Improves Its Obfuscation Techniques and Expands to Other Asian Countries

Published on

SIEM as a Service

Follow Us on Google News

Magniber ransomware emerges again leveraging various obfuscation techniques and with refined source codes. The most famous and long-running browser exploitation toolkit Magnitude delivering Magniber ransomware, and the toolkit primarily uses Zero-day remote code execution vulnerability allows an attacker could execute arbitrary code and take the complete control of the infected system (CVE-2018-8174).

Previously Magniber targets only South Korea, now it expanded geographically and targets Asia Pacific countries.

Security researchers from Malwarebytes labs spotted the Magniber with various obfuscation techniques and no longer dependent on a Command and Control server or hardcoded key for its encryption routine.

- Advertisement - Google News

Magniber Ransomware Execution

Magniber ransomware download and execution is multi-staged, it uses obfuscated VBScript and JavaScript. After the exploitation of the vulnerability in Internet Explorer, the XOR-encrypted Magniber is retrieved.

“Each time a new file is going to be encrypted, two 16-byte long strings are generated. One will be used as an AES key, and another as an initialization vector (IV). Below you can see the fragment of code responsible for generating those pseudo-random strings.”

The new version of Magniber ransomware comes with a public RSA key which makes it complete the encryption process without an Internet connection. It uses to encrypt the file and ads ransom note named README.txt and the file extension is [.]dyaaghemy.

Magniber ransomware
Image Credits: Malwarebytes

It displays a ransom note and asks to make payment of 0.35 BTC within 5 days to recover the files encrypted.

Magniber ransomware
Image Credits: Malwarebytes

Researchers said the code fully was rewritten over time and it’s list expanded adding other Asian languages, such as Chinese (Macau, China, Singapore) and Malay (Malysia, Brunei). Magniber ransomware would install only if a specific country code was returned, else it would delete by itself.

Also Read

New Version of GandCrab Ransomware Attack via Compromised Websites using SMB Exploit Spreader

Hackers Distributing Malicious PDF that Perform both Ransomware and Crypto-Mining Attack

New Version of SamSam Ransomware Attack Targeted Victims with Sophisticated Evasion Techniques

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Ransomware Attacks Surge 126%, Targeting Consumer Goods and Services Sector

The cybersecurity landscape witnessed a dramatic escalation in ransomware attacks, marking a concerning trend...

CrazyHunter Hacker Group Exploits Open-Source GitHub Tools to Target Organizations

A relatively new ransomware outfit known as CrazyHunter has emerged as a significant threat,...

Threat Actors Leverage Cascading Shadows Attack Chain to Evade Detection and Hinder Analysis

A sophisticated multi-layered phishing campaign was uncovered, employing a complex attack chain known as...

Microsoft Vulnerabilities Reach Record High with Over 1,300 Reported in 2024

The 12th Edition of the Microsoft Vulnerabilities Report has revealed a significant surge in...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Ransomware Attacks Surge 126%, Targeting Consumer Goods and Services Sector

The cybersecurity landscape witnessed a dramatic escalation in ransomware attacks, marking a concerning trend...

CrazyHunter Hacker Group Exploits Open-Source GitHub Tools to Target Organizations

A relatively new ransomware outfit known as CrazyHunter has emerged as a significant threat,...

Ghost Ransomware Targets Organizations Across 70+ Countries

A new ransomware variant known as "Ghost" (also referred to as Cring) has emerged...