• News/
  • https://www.bleepingcomputer.com/news/security/magnet-goblin-hackers-use-1-day-flaws-to-drop-custom-linux-malware/

Magnet Goblin hackers use 1-day flaws to drop custom Linux malware

BleepingComputer
·
Bill Toulas
·
Published Mar 9, 2024
·
Updated

A financially motivated hacking group named Magnet Goblin uses various 1-day vulnerabilities to breach public-facing servers and deploy custom malware on Windows and Linux systems. 1-day flaws refer to publicly disclosed vulnerabilities for which a patch has been released. Threat actors looking to exploit these flaws must do so quickly before a target can apply security updates. Though exploits are usually not made available immediately upon a flaw's disclosure, some vulnerabilities are trivial to figure out how to leverage. Additionally, reverse-engineering the patch may reveal the underlying problem and how to exploit it. Check Point analysts who identified Magnet Goblin report that these threat actors are quick to exploit newly disclosed vulnerabilities, in some cases exploiting flaws a day after a PoC exploit is released. Some of the devices or services targeted by the hackers are Ivanti Connect Secure (CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, CVE-2024-21893., Apache ActiveMQ, ConnectWise ScreenConnect, Qlik Sense (CVE-2023-41265, CVE-2023-41266, CVE-2023-48365), and Magento (CVE-2022-24086). Magnet Goblin exploits the flaws to infect servers with custom malware, particularly NerbianRAT and MiniNerbian, as well as a custom variant of the WARPWIRE JavaScript stealer. NerbianRAT for Windows has been known since 2022, but Check Point now reports that a sloppily compiled yet effective Linux variant used by Magnet Goblin has been in circulation since May 2022. Upon firs...

Read full article

Affected Software

5 affected components
Ivanti Connect Secure
Apache ActiveMQ
ConnectWise ScreenConnect
Qlik Sense
Magento Magento

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how the Magnet Goblin hacking group exploits 1-day vulnerabilities to deploy custom malware on systems.

2

What security implications are discussed in the article?

The article highlights the risks associated with unpatched vulnerabilities being exploited to gain unauthorized access and deploy malware.

3

What products or software are affected by the vulnerabilities mentioned?

Affected software includes Ivanti Connect Secure, Apache ActiveMQ, ConnectWise ScreenConnect, Qlik Sense, and Magento.

4

Who is the group behind these attacks?

The hacking group responsible for these attacks is called Magnet Goblin.

5

What types of systems are targeted by the hackers?

The attackers target both Windows and Linux systems exposed through public-facing servers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203