logo

Cybercrime crew Magnet Goblin bursts onto the scene exploiting Ivanti holes

ID: 2d932509-7a55-54a7-8462-0445a597f9a7

STIX ID: report--2d932509-7a55-54a7-8462-0445a597f9a7

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-03-08

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Check Point observed a financially motivated group called Magnet Goblin rapidly exploiting newly disclosed Ivanti Connect Secure VPN vulnerabilities (often within one day of PoC release) to compromise US organizations in the medical, manufacturing, and energy sectors. The intrusions involved deploying Linux backdoors (MiniNerbian, NerbianRAT), a JavaScript credential stealer (WARPWIRE), and leveraging legitimate remote admin tools (ScreenConnect, AnyDesk); the group is linked to other edge-product exploits (Qlik Sense) and connections to Cactus ransomware activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.