Magnify.exe

by Microsoft
Operating Systemmedium risk

Sources: 300M+ executions observed in the wild.

Summary

Windows Magnifier accessibility tool. Same class of backdoor target as utilman.exe and sethc.exe — can be replaced or redirected via IFEO to provide SYSTEM-level access from the login screen.

Magnify.exe is the 2711th most commonly executed Windows program in EchoTrail's dataset, observed 133 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by AtBroker.exe.

Get this in your tools

The same record for magnify.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/magnify.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

2711th
most commonly executed Windows program
133
observed endpoint executions

Behavior

Top Paths

  • C:\Windows\System32100%

Top Hashes (SHA256)

  • 23062bb7bcc544fbca33d4ff1865242a2d6d98c8cdc7b56163efcab9da80137844.27%
  • 41e91d736995628275261aa1adb14158e0783b36c913ef5fc681da105a4272cc44.27%
  • 72a31aeb7655343c7112085dfd49a2d5f1a6f1191d8f91a96bc446de932724ea6.11%
  • 34569826cf411c364eabf23ae36a4a01e017300db3b5d8007ab71b8643ed7bd11.53%
  • 360cbaa2ef0f314af6fb364d664a02403a06736b8a301af228c344bef75672741.53%
  • 9b9dbcf53c4850d13a3e2bd0822054f1d41be66645727592ffb5c4ac6a36e4591.53%
  • 95096f5a9de28c2d075565faa198ed55322367a483e43e3e31126acb30d5f81e0.76%

Process Ancestry

Top Grandparents

Top Parents

Security Analysis

What does Magnify.exe normally do?

Runs from C:\Windows\System32. Screen magnification tool accessible from login screen Ease of Access menu or Win+Plus shortcut. Persists while user is using magnification.

When is Magnify.exe suspicious?

Binary replacement (hash change). IFEO debugger key set. Spawning cmd.exe, powershell.exe, or shells. Running from non-System32 path.

How do attackers abuse Magnify.exe?

ACCESSIBILITY BACKDOOR: Same technique as utilman.exe/sethc.exe. Replace magnify.exe with cmd.exe or set IFEO debugger key. Invoke via Ease of Access at login screen for SYSTEM shell. Less commonly targeted than sethc.exe or utilman.exe but still a viable vector.

Detection guidance

HIGH-CONFIDENCE: File hash change for magnify.exe. IFEO debugger key for magnify.exe. magnify.exe spawning shells. DATA SOURCES: File integrity monitoring, registry events (Sysmon 12/13), process creation (Sysmon 1)

False positive notes

Legitimate accessibility use. Windows Updates may modify the binary.

MITRE ATT&CK techniques

References

Related Processes

Ask Rocky about Magnify.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for Magnify.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.