Magnet Goblin Hacker Group Leveraging 1-Day Exploits to Deploy Nerbian RAT
ID: 16a574a8-0f82-5ea9-b414-d9dff4a468dc
STIX ID: report--16a574a8-0f82-5ea9-b414-d9dff4a468dc
Feed Name: The Hacker News
Magnet Goblin is a financially motivated threat actor that rapidly weaponizes one-day vulnerabilities against public-facing servers and edge devices (e.g., Ivanti Connect Secure, Magento, Qlik Sense) to gain access and deploy Linux and cross-platform remote access trojans (Nerbian RAT and MiniNerbian). The group also uses credential stealers (WARPWIRE), tunneling tools (Ligolo), and legitimate remote desktop software to maintain access and exfiltrate data, with exploit deployment observed within a day of public proof-of-concept releases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
