Surge in Magniber ransomware attacks impact home users worldwide

Share:

A massive Magniber ransomware campaign is underway, encrypting home users’ devices worldwide and demanding thousand-dollar ransoms to receive a decryptor.

Magniber launched in 2017 as a successor to the Cerber ransomware operation when it was spotted being distributed by the Magnitude exploit kit.

Since then, the ransomware operation has seen bursts of activity over the years, with the threat actors utilizing various methods to distribute Magniber and encrypt devices. These tactics include using Windows zero-days,  fake Windows and browser updates, and trojanized software cracks and key generators.

Unlike the larger ransomware operations, Magniber has primarily targeted individual users who download malicious software and execute it on their home or small business systems.

In 2018, AhnLab released a decryptor for the Magniber ransomware. However, it no longer works as the threat actors fixed the bug allowing free file decryption.

Ongoing Magniber campaign

Since July 20, BleepingComputer has seen a surge in Magniber ransomware victims seeking help in our forums.

Ransomware identification site ID-Ransomware has also seen a surge, with almost 720 submissions to the site since July 20, 2024.

While it unclear how victims are being infected, BleepingComputer has been told by a few victims that their device was encrypted after running software cracks or key generators, which is a method the threat actors used in the past.

Once launched, the ransomware encrypts files on the device and appends a random 5-9 character extension, like .oaxysw or .oymtk, to encrypted file names.

The ransomware will also create a ransom note named READ_ME.htm, which contains information about what happened to a person’s files and a unique URL to the threat actor’s Tor ransom site.

As Magniber typically targets consumers, the ransom demands start at $1,000 and then increase to $5,000 if a Bitcoin payment is not made within three days.

Unfortunately, there is no way to decrypt files encrypted by the current versions of Magniber for free.

It is strongly advised to avoid software cracks and key generators as it’s not only illegal but also a common method used to distribute malware and ransomware.

For those impacted by the ransomware, you can use our dedicated Magniber support topic to receive help or receive answers to questions.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:23 am, Jan 22, 2025
weather icon 3°C
L: 2° | H: 4°
mist
Humidity: 91 %
Pressure: 1008 mb
Wind: 2 mph
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 5 km
Sunrise: 7:52 am
Sunset: 4:31 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
2° | 4°°C 1 mm 100% 5 mph 95 % 1008 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
2° | 8°°C 1 mm 100% 17 mph 94 % 1005 mb 0 mm/h
Fri Jan 24 9:00 pm
weather icon
6° | 10°°C 1 mm 100% 24 mph 91 % 1004 mb 0 mm/h
Sat Jan 25 9:00 pm
weather icon
4° | 6°°C 0.89 mm 89% 8 mph 86 % 1012 mb 0 mm/h
Sun Jan 26 9:00 pm
weather icon
5° | 8°°C 0.2 mm 20% 14 mph 86 % 1011 mb 0 mm/h
Today 3:00 am
weather icon
3° | 3°°C 0 mm 0% 3 mph 92 % 1008 mb 0 mm/h
Today 6:00 am
weather icon
3° | 3°°C 0.8 mm 80% 3 mph 95 % 1006 mb 0 mm/h
Today 9:00 am
weather icon
4° | 4°°C 1 mm 100% 3 mph 95 % 1004 mb 0 mm/h
Today 12:00 pm
weather icon
4° | 4°°C 0.8 mm 80% 4 mph 91 % 1003 mb 0 mm/h
Today 3:00 pm
weather icon
4° | 4°°C 0 mm 0% 5 mph 89 % 1002 mb 0 mm/h
Today 6:00 pm
weather icon
3° | 3°°C 0 mm 0% 3 mph 87 % 1003 mb 0 mm/h
Today 9:00 pm
weather icon
2° | 2°°C 0 mm 0% 4 mph 95 % 1004 mb 0 mm/h
Tomorrow 12:00 am
weather icon
2° | 2°°C 0 mm 0% 3 mph 94 % 1004 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€101,439.62
3.76%
Ethereum(ETH)
€3,197.76
2.67%
XRP(XRP)
€3.05
0.41%
Tether(USDT)
€0.96
0.14%
Solana(SOL)
€241.25
5.36%
Dogecoin(DOGE)
€0.354500
6.02%
USDC(USDC)
€0.96
0.00%
Shiba Inu(SHIB)
€0.000020
3.44%
Pepe(PEPE)
€0.000015
2.37%
Peanut the Squirrel(PNUT)
€0.358531
-0.90%
Scroll to Top