logo

Magniber ransomware actors used a variant of Microsoft SmartScreen bypass

ID: cc1377f6-4f42-55ae-9672-c47dd1d21200

STIX ID: report--cc1377f6-4f42-55ae-9672-c47dd1d21200

Feed Name: Google's Threat Analysis Group (TAG)

Threat Score
70/100

Date Published: 2023-03-14

Date Updated: 2026-04-27

Author: Benoit Sevens

...
...

The report outlines September–November 2022 Magniber ransomware activity that used malformed Authenticode signatures to bypass SmartScreen warnings (an issue later tracked as CVE-2022-44698). Initially deployed via JScript, the actors switched to MSI installers in the current campaign; other actors (notably Qakbot operators) later reused the same bypass. Microsoft released a patch in December 2022.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.