Magniber ransomware actors used a variant of Microsoft SmartScreen bypass
ID: cc1377f6-4f42-55ae-9672-c47dd1d21200
STIX ID: report--cc1377f6-4f42-55ae-9672-c47dd1d21200
Feed Name: Google's Threat Analysis Group (TAG)
Threat Score
The report outlines September–November 2022 Magniber ransomware activity that used malformed Authenticode signatures to bypass SmartScreen warnings (an issue later tracked as CVE-2022-44698). Initially deployed via JScript, the actors switched to MSI installers in the current campaign; other actors (notably Qakbot operators) later reused the same bypass. Microsoft released a patch in December 2022.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
