#Magniber

Malware/Tool

2017-10-17 • Magniber ransomware: exclusively for South Koreans

Magniber is Windows ransomware that encrypts victim files and demands cryptocurrency for recovery. It has particularly targeted systems using Korean language settings or South Korean IP addresses, and encrypted files receive a randomly generated lowercase extension that differs by host. Distribution has included typosquatted websites and rapidly changing detection-evasion tests. Korean prosecutors documented a recovery-service scheme that cooperated with the operators over several years; traced funds suggested a possible link between the distribution organization and Lazarus, but this attribution remained an assessment.

Tagged Reports

« Back