Magnify.exe
Summary
Windows Magnifier accessibility tool. Same class of backdoor target as utilman.exe and sethc.exe — can be replaced or redirected via IFEO to provide SYSTEM-level access from the login screen.
Magnify.exe is the 2711th most commonly executed Windows program in EchoTrail's dataset, observed 133 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by AtBroker.exe.
Behavior
Top Paths
- C:\Windows\System32100%
Top Hashes (SHA256)
- 23062bb7bcc544fbca33d4ff1865242a2d6d98c8cdc7b56163efcab9da80137844.27%
- 41e91d736995628275261aa1adb14158e0783b36c913ef5fc681da105a4272cc44.27%
- 72a31aeb7655343c7112085dfd49a2d5f1a6f1191d8f91a96bc446de932724ea6.11%
- 34569826cf411c364eabf23ae36a4a01e017300db3b5d8007ab71b8643ed7bd11.53%
- 360cbaa2ef0f314af6fb364d664a02403a06736b8a301af228c344bef75672741.53%
- 9b9dbcf53c4850d13a3e2bd0822054f1d41be66645727592ffb5c4ac6a36e4591.53%
- 95096f5a9de28c2d075565faa198ed55322367a483e43e3e31126acb30d5f81e0.76%
Process Ancestry
Top Grandparents
- AtBroker.exe51.56%
- winlogon.exe28.12%
- explorer.exe14.06%
- userinit.exe6.25%
Top Parents
- AtBroker.exe92.48%
- explorer.exe7.52%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does Magnify.exe normally do?
Runs from C:\Windows\System32. Screen magnification tool accessible from login screen Ease of Access menu or Win+Plus shortcut. Persists while user is using magnification.
When is Magnify.exe suspicious?
Binary replacement (hash change). IFEO debugger key set. Spawning cmd.exe, powershell.exe, or shells. Running from non-System32 path.
How do attackers abuse Magnify.exe?
ACCESSIBILITY BACKDOOR: Same technique as utilman.exe/sethc.exe. Replace magnify.exe with cmd.exe or set IFEO debugger key. Invoke via Ease of Access at login screen for SYSTEM shell. Less commonly targeted than sethc.exe or utilman.exe but still a viable vector.
Detection guidance
HIGH-CONFIDENCE: File hash change for magnify.exe. IFEO debugger key for magnify.exe. magnify.exe spawning shells. DATA SOURCES: File integrity monitoring, registry events (Sysmon 12/13), process creation (Sysmon 1)
False positive notes
Legitimate accessibility use. Windows Updates may modify the binary.
MITRE ATT&CK techniques
Related Processes
Ask Rocky about Magnify.exe
Rocky answers questions about Magnify.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.