ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Magniber ransomware targets Windows home users via fake security updates

Linked InXFacebook
bookmark_borderSave to Library

HP’s Threat Intelligence team has revealed that Magniber ransomware, known as a single-client ransomware family that demands $2,500 from victims to release decryptors, is currently targeting Windows home users by masquerading as a software update, often promoted on malicious websites.

 

The fake security update contains a malicious JavaScript file that can trigger a complicated infection with the file-encrypting malware. Magniber spread through MSI and EXE files earlier, but in September, the researchers at HP Wolf Security discovered a new ransomware strain distributing the ransomware in JavaScript files.

 

The ransomware operators use Chrome and Edge browser updates to push malicious Windows application package files (.APPX) on Windows 10 and 11. According to HP Wolf Security, the attackers employed cunning strategies to avoid detection, including running the ransomware in memory, getting around Windows’ User Account Control (UAC), and dodging detection tools that keep an eye on user-mode hooks by using syscalls rather than the default Windows API libraries.

 

The malware disables backup and recovery features and deletes the shadow copy files on the compromised system using the UAC bypass, preventing the victim from using Windows tools to recover their data.

 

HP Wolf noted that the infection chain for the ransomware campaign begins with a web download from a website under the attacker’s control. The user is prompted to download a ZIP file with a JavaScript file that purports to be a crucial Windows 10 software update. Magniber needs to be executed on a Windows account with administrator privileges to access and block files. This level of access is much more commonplace in personal systems.

 

Home users can protect themselves by regularly backing up their files and maintaining an offline storage device. They can further protect themselves by adhering to the “least-privilege” principle, which dictates that they should only use their administrator account when necessary and make another account for regular use. Users can also lower the risk by checking URLs to ensure they are using the official vendor websites, installing updates only from reputable sources, and regularly backing up data to lessen the effects of a potential data breach.

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543