The Magniber ransomware gang now appears to be using two Internet Explorer vulnerabilities and malicious ads to infect users and encrypt their devices.
The two vulnerabilities of Internet Explorer are referred to as CVE-2021-26411 and CVE-2021-40444 – and both have a CVSS v3 severity score of 8.8.
See also: Ransomware – Ransom: How much do victims pay?

The first, CVE-2021-26411, was patched in March 2021 and is a memory corruption flaw triggered by rendering a specially crafted website.
The second flaw, CVE-2021-40444, is a remote code execution vulnerability in the Internet Explorer rendering engine that is triggered by opening a malicious document.
The intruders exploited CVE-2021-40444 as a zero-day before Microsoft patched it in September 2021.
See also: MediaMarkt hit by Hive ransomware
Magniber focus shift
The Magniber gang is known for using vulnerabilities to breach systems and develop their ransomware.
In August, it was observed that Magniber was exploiting the vulnerabilities of «PrintNightmare» to breach Windows servers, which took Microsoft a short time to address due to their impact on printing.
Magniber's most recent activity focuses on exploiting Internet Explorer vulnerabilities using malicious advertising that pushes to Windows servers, as confirmed by Tencent Security researchers who identified "new" payloads.
A possible explanation for this shift is that Microsoft has been patching the “PrintNightmare” vulnerabilities for the past four months and has been pushing administrators to apply the updates.
Another reason why Magniber may have turned to Internet Explorer flaws is that they are relatively easy to activate, relying solely on piqued the recipient's curiosity to open a file or web page.
It may seem odd to target an old, unpopular browser like Internet Explorer. However, StatCounter shows that 1.15% of global page views still come from IE.
See also: Ransomware cyberattack on Danaos and Greek shipping companies
Even though this is a low percentage, StatCounter monitors over 10 billion page views per month, which equates to 115,000,000 page views from Internet Explorer users.
Furthermore, it is much harder to target browsers based on Firefox and Chromium, such as Google Chrome and Microsoft Edge, as they use an automatic update mechanism that protects users from known vulnerabilities.
Threat to Asian companies
The Magniber group began in 2017 as the successor to the ransomware and initially only infected users from South Korea.
Subsequently, the group broadened its targeting scope and began infecting systems from China, Singapore, and Malaysia.

This attack surface has stabilized and today, Magniber exclusively bothers Asian companies and organizations.
From its release, the Magniber ransomware has evolved very actively and its payload has been completely rewritten three times.
Currently, it remains uncracked, so there is no decryptor to help you restore any files that have been encrypted with this strain.
Finally, Magniber does not follow the trend of file theft and double extortion, so the damage from their attacks is limited to file encryption.
Therefore, taking regular backups on secure, isolated systems is a very effective way to address this threat.
Information source: bleepingcomputer.com
