logo

Magnet Goblin Hacker Group Leveraging 1-Day Exploits to Deploy Nerbian RAT

ID: 16a574a8-0f82-5ea9-b414-d9dff4a468dc

STIX ID: report--16a574a8-0f82-5ea9-b414-d9dff4a468dc

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-03-11

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Magnet Goblin is a financially motivated threat actor that rapidly weaponizes one-day vulnerabilities against public-facing servers and edge devices (e.g., Ivanti Connect Secure, Magento, Qlik Sense) to gain access and deploy Linux and cross-platform remote access trojans (Nerbian RAT and MiniNerbian). The group also uses credential stealers (WARPWIRE), tunneling tools (Ligolo), and legitimate remote desktop software to maintain access and exfiltrate data, with exploit deployment observed within a day of public proof-of-concept releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.