A financially motivated hacking group named Magnet Goblin uses various 1-day vulnerabilities to breach public-facing servers and deploy custom malware on Windows and Linux systems. 1-day flaws refer to publicly disclosed vulnerabilities for which a patch has been released. Threat actors looking to exploit these flaws must do so quickly before a target can apply security updates. Though exploits are usually not made available immediately upon a flaw's disclosure, some vulnerabilities are trivial to figure out how to leverage. Additionally, reverse-engineering the patch may reveal the underlying problem and how to exploit it. Check Point analysts who identified Magnet Goblin report that these threat actors are quick to exploit newly disclosed vulnerabilities, in some cases exploiting flaws a day after a PoC exploit is released. Some of the devices or services targeted by the hackers are Ivanti Connect Secure (CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, CVE-2024-21893., Apache ActiveMQ, ConnectWise ScreenConnect, Qlik Sense (CVE-2023-41265, CVE-2023-41266, CVE-2023-48365), and Magento (CVE-2022-24086). Magnet Goblin exploits the flaws to infect servers with custom malware, particularly NerbianRAT and MiniNerbian, as well as a custom variant of the WARPWIRE JavaScript stealer. NerbianRAT for Windows has been known since 2022, but Check Point now reports that a sloppily compiled yet effective Linux variant used by Magnet Goblin has been in circulation since May 2022. Upon firs...
Magnet Goblin hackers use 1-day flaws to drop custom Linux malware
BleepingComputer
·Bill Toulas
·Published Mar 9, 2024
·Updated
Affected Software
5 affected components
Ivanti Connect Secure
Apache ActiveMQ
ConnectWise ScreenConnect
Qlik Sense
Magento Magento
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how the Magnet Goblin hacking group exploits 1-day vulnerabilities to deploy custom malware on systems.
2
What security implications are discussed in the article?
The article highlights the risks associated with unpatched vulnerabilities being exploited to gain unauthorized access and deploy malware.
3
What products or software are affected by the vulnerabilities mentioned?
Affected software includes Ivanti Connect Secure, Apache ActiveMQ, ConnectWise ScreenConnect, Qlik Sense, and Magento.
4
Who is the group behind these attacks?
The hacking group responsible for these attacks is called Magnet Goblin.
5
What types of systems are targeted by the hackers?
The attackers target both Windows and Linux systems exposed through public-facing servers.