Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check Point Research reported in March 2024 that Magnet Goblin rapidly exploited newly disclosed flaws in public-facing services and edge devices, sometimes within a day after a proof of concept appeared. In an Ivanti Connect Secure VPN campaign, the actor deployed Linux malware including a NerbianRAT variant, alongside a JavaScript credential stealer and a tunneling tool. This is a record of reported 2024 activity—not evidence of the actor’s current activity or today’s patch status.

What “one-day vulnerabilities” means in this campaign

Check Point Research described Magnet Goblin as an actor it tracks and characterizes as financially motivated. Its 8 March 2024 report said the group moved quickly to use newly disclosed vulnerabilities against internet-facing services. In some cases, exploitation followed publication of a proof of concept within one day. That is an observation about some reported activity, not a claim that every vulnerability was exploited exactly one day after disclosure or a measured exploitation rate. Check Point Research’s campaign report

A proof of concept demonstrates or explains how a vulnerability can be exploited; its publication can make a flaw easier for attackers to operationalize. The reporting’s “one-day” wording describes the short interval after proof-of-concept publication, not necessarily the interval after the original vulnerability disclosure.

Which services and devices were associated with Magnet Goblin?

Check Point associated the actor with attacks involving Ivanti Connect Secure VPN, Magento, and Qlik Sense, and described Apache ActiveMQ targeting as possible. SecurityWeek’s 11 March 2024 coverage listed the following vulnerability associations from the reporting:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Learn How to Use Linux, Ubuntu Linux 22.04 Bootable 8GB USB Flash Drive - Includes Boot Repair and Install Guide Now with USB Type C
  • Ubuntu Linux 22 on a Bootable 8 GB USB type C OTG phone compatible storage
  • The preinstalled USB stick allows you to learn how to learn to use Linux, boot and load Linux without uninstalling your current OS
  • Comes with an easy-to-follow install guide. 24/7 software support via email included.
  • Comprehensive installation includes lifetime free updates and multi-language support, productivity suite, Web browser, instant messaging, image editing, multimedia, and email for your everyday needs
  • Boot repair is a very useful tool! This USB drive will work on all modern-day computers, laptops or desktops, custom builds or manufacture built!
Service or platform Vulnerability IDs cited in 2024 coverage Qualification
Ivanti Connect Secure VPN CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, CVE-2024-21893 Associated with the reported campaign; Symantec/Broadcom specifically identified exploitation of CVE-2024-21887.
Magento CVE-2022-24086 Listed in SecurityWeek’s coverage of the reported actor associations.
Qlik Sense CVE-2023-41265, CVE-2023-41266, CVE-2023-48365 Listed in SecurityWeek’s coverage of the reported actor associations.
Apache ActiveMQ Not stated in the cited coverage Check Point described targeting as possible, not confirmed.

The vulnerability list reflects March 2024 campaign reporting, not a current affected-version list or present-day exploitation assessment. SecurityWeek’s 11 March 2024 report

What Linux malware and tools appeared in the Ivanti campaign?

Linux NerbianRAT

While tracking exploitation of Ivanti systems, Check Point researchers found activity that downloaded and deployed an ELF file they identified as a Linux variant of NerbianRAT. An ELF file is a standard executable format used on Linux systems. Symantec/Broadcom’s 11 March 2024 bulletin independently summarized deployment of Linux NerbianRAT in the campaign and identified CVE-2024-21887, an Ivanti Connect Secure web-component command injection vulnerability, as exploited. Symantec/Broadcom’s campaign summary

WARPWIRE credential stealer

Check Point described WARPWIRE as a JavaScript credential stealer. Symantec/Broadcom also reported its deployment alongside Linux NerbianRAT. Its presence shows that the campaign included credential theft as well as Linux backdoor activity; the reporting does not establish the full scope of compromised accounts.

Ligolo and MiniNerbian

Check Point also reported Ligolo, an open-source tunneling tool written in Go, and discussed MiniNerbian, a smaller Linux backdoor, as part of the broader toolset. The report presents these as components of the activity it tracked, not as proof that every affected system received every tool.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the reporting does—and does not—establish

CERT-EU’s March 2024 brief summarized Check Point’s findings, including rapid use of newly disclosed flaws and the Ivanti campaign’s Linux NerbianRAT and WARPWIRE. Together, these March reports describe historical targeting of exposed enterprise services and edge devices. They do not establish whether Magnet Goblin remains active, whether any listed flaw is currently being exploited, or whether a particular installation is patched today. CERT-EU’s March 2024 brief

Administrators assessing risk now should use current official advisories from the relevant product vendors and government cybersecurity authorities to confirm affected versions, mitigations, and patch status. The 2024 actor reporting is useful context for why exposed systems warrant attention, but it is not a substitute for a current remediation guide.

Quick Recap

Bestseller No. 1
Learn How to Use Linux, Ubuntu Linux 22.04 Bootable 8GB USB Flash Drive - Includes Boot Repair and Install Guide Now with USB Type C
Learn How to Use Linux, Ubuntu Linux 22.04 Bootable 8GB USB Flash Drive - Includes Boot Repair and Install Guide Now with USB Type C
Ubuntu Linux 22 on a Bootable 8 GB USB type C OTG phone compatible storage; Comes with an easy-to-follow install guide. 24/7 software support via email included.
$22.95
Bestseller No. 4
Learn How to Use Linux, Linux Mint Cinnamon 22 Bootable 8GB USB Flash Drive - Includes Boot Repair and Install Guide Now with USB Type C
Learn How to Use Linux, Linux Mint Cinnamon 22 Bootable 8GB USB Flash Drive - Includes Boot Repair and Install Guide Now with USB Type C
Linux Mint 22 on a Bootable 8 GB USB type C OTG phone compatible storage; Comes with an easy-to-follow install guide. 24/7 software support via email included.
$22.95
Rank #4
Learn How to Use Linux, Linux Mint Cinnamon 22 Bootable 8GB USB Flash Drive - Includes Boot Repair and Install Guide Now with USB Type C
  • Linux Mint 22 on a Bootable 8 GB USB type C OTG phone compatible storage
  • The preinstalled USB stick allows you to learn how to learn to use Linux, boot and load Linux without uninstalling your current OS
  • Comes with an easy-to-follow install guide. 24/7 software support via email included.
  • Comprehensive installation includes lifetime free updates and multi-language support, productivity suite, Web browser, instant messaging, image editing, multimedia, and email for your everyday needs
  • Boot repair is a very useful tool! This USB drive will work on all modern-day computers, laptops or desktops, custom builds or manufacture built!

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.