Skip to content
Attackers Compile Cryptominer on Victim Endpoint via Samsung MagicINFO Exploit

Attackers Compile Cryptominer on Victim Endpoint via Samsung MagicINFO Exploit

First seen 25 Sep 2026, 14:27 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 25, 2026 at 15:53 UTC
  • •Attackers exploited CVE-2025-4632 in Samsung MagicINFO to gain access.
  • •A cryptominer was compiled directly on the victim's machine, increasing detection risk.
  • •Organizations should monitor for unexpected compiler activity and patch vulnerabilities.

In early September 2026, a threat actor exploited CVE-2025-4632, a vulnerability in Samsung MagicINFO, to compile a cryptominer directly on a victim's endpoint. The attack began with the installation of a rogue AnyDesk instance after multiple failed attempts, followed by creating a new local admin account and disabling Microsoft Defender. The attacker utilized the Silent XMR Miner Builder to compile the miner, which generated significant EDR telemetry, making the intrusion noticeable. Despite the organization being alerted to the initial compromise, the same endpoint was flagged again for malicious activity shortly thereafter. This incident highlights the importance of monitoring for unusual compiler activity and patching known vulnerabilities promptly.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-05-13
CVE-2025-4632 published
A vulnerability in Samsung MagicINFO allowing arbitrary file writing with system privileges was disclosed.
Huntress
2026-04-24
CVE-2024-7399 added to CISA KEV
CISA listed the incomplete fix for a previous vulnerability in Samsung MagicINFO as actively exploited.
Huntress
2026-09-01
Initial compromise detected
Huntress observed unusual activity linked to Samsung MagicINFO on a managed endpoint.
Huntress
2026-09-09
Malicious activity flagged again
The same endpoint was flagged for new malicious activity tied to the initial access route.
Itsecurityguru
2026-09-25
Incident reported
Huntress published findings on the unique attack involving on-endpoint miner compilation.
Itsecurityguru

More articles in this cluster (3)

Following this threat?

Track SilentXMRMiner and CVE-2024-7399 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed