Recent observations of the Magniber ransomware have revealed that the recent campaign that uses Magniber ransomware has been targeting Windows home users with fake security updates. It was observed in September that the threat actors had created websites that promoted fake antivirus and security updates for Windows 10. These websites hosted malicious ZIP archives that contained JavaScript that initiated an intricate infection with the file-encrypting malware.
The threat group has previously been observed distributing the ransomware as a Windows 10 update in April 2022 and other campaigns have been using MSI and EXE files.
Threat intelligence sources have stated that they have seen the Magniber ransomware operators demand payment of up to $2,500 for home users to receive a decryption tool and recover their files. The strain focuses explicitly on Windows 10 and Windows 11 builds.
© 2021 CyberEnsō – Nihon Cyber Defence Co., Ltd. All Rights Reserved.