A financially motivated hacking group called Magnet Goblin is using various 1-day vulnerabilities to compromise servers affecting public users and deploy custom malware on Windows and Linux systems.
See also: GTPDOOR Linux malware exploits GPRS networks

1-day bugs refer to vulnerabilities that have been publicly disclosed and for which a patch has been released. Malicious actors who want to exploit these flaws must do so quickly before a target can apply security updates.
analysts who discovered Magnet Goblin report that these hackers are quickly exploiting newly disclosed vulnerabilities, in some cases exploiting flaws 1-day after a PoC, to distribute Linux Malware.
Some of the devices or services targeted by hackers include Ivanti Connect Secure (CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, CVE-2024-21893., Apache ActiveMQ, ConnectWise ScreenConnect (, -2023-41265, CVE-2023-41266, CVE-2023-48365) and Magento (CVE-2022-24086).
Magnet Goblin exploits the flaws to infect servers with custom malware, particularly NerbianRAT and MiniNerbian, as well as a custom variant of the WARPWIRE JavaScript stealer.
NerbianRAT for Windows has been known since 2022, but Check Point now reports that an improperly compiled but effective variant of the malware for Linux, used by Magnet Goblin, has been circulating since May 2022.
Upon first launch, the malware performs preliminary actions, including collecting system information such as time, username, and machine name, generating a bot, setting a hardcoded IP address as the primary and secondary host ,setting the working directory, and loading an RSA public key for encrypting (AES) network communication.
After that, NerbianRAT loads its configuration, which specifies activity times (work time), time intervals for communication with the command and control (C2) server, and other parameters.
See also: Company announcement about the Free Download Manager site that spread Linux malware

The C2 can send one of the following actions to the malware to execute on the infected system:
- Perform more actions
- Running a Linux command in a new thread
- Sending command result and cleaning the file
- Execute a Linux command directly
- Complete hibernation
- Modify connection interval
- Adjust and save work time settings
- Return results of idle, configuration, or command timings
- Update a specific configuration variable
- Refresh buffer for C2 execution commands
MiniNerbian is a simplified version of NerbianRAT, which is mainly used for executing commands and supports the following actions:
- Execute C2 command and return results
- Update activity schedule (all day or specific hours)
- Configuration update
MiniNerbian communicates with the C2 via HTTP, differentiating it from the more complex NerbianRAT, which uses raw TCP sockets for communication.
Check Point says that identifying specific threats like attacks among the vast volume of 1-day exploit data, as in the case of Linux malware, is difficult, allowing these groups to hide in plain sight in the chaos that follows flaw disclosure.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: ANY.RUN Sandbox: Allows SOC and DFIR teams to analyze advanced Linux malware

How can we protect ourselves from '1-day flaws'?
To protect yourself from 1-day flaws, such as those exploited by Magnet Goblin to distribute Linux malware, we must first understand the importance of keeping our software up to date. Updates often include fixes for known vulnerabilities, thus preventing their exploitation. In addition, using security tools, such as antivirus and intrusion prevention systems, can help detect and prevent attacks that exploit these vulnerabilities. Finally, implementing security best practices, such as using strong passwords, securing network connections, and limiting the use of administrator, can reduce the likelihood of a successful attack.
Source: bleepingcomputer
