logo

Magnet Goblin hackers use 1-day flaws to drop custom Linux malware

ID: b53ae6a8-3c59-55a6-b1d5-760b2a3c9d8a

STIX ID: report--b53ae6a8-3c59-55a6-b1d5-760b2a3c9d8a

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-03-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Magnet Goblin is a financially motivated hacking group that quickly exploits publicly disclosed 1-day vulnerabilities in products like Ivanti Connect Secure, Apache ActiveMQ, Qlik Sense, ConnectWise ScreenConnect, and Magento to infect servers with custom Windows and Linux malware (NerbianRAT, MiniNerbian) and a JavaScript stealer; the report describes malware behaviors, C2 actions, and emphasizes rapid patching and standard mitigations to reduce impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.