Itsecurityguru Attackers Compile Cryptominer on Victim Endpoint via Samsung MagicINFO Exploit
Article Content
- •Attackers exploited CVE-2025-4632 in Samsung MagicINFO to gain access.
- •A cryptominer was compiled directly on the victim's machine, increasing detection risk.
- •Organizations should monitor for unexpected compiler activity and patch vulnerabilities.
In early September 2026, a threat actor exploited CVE-2025-4632, a vulnerability in Samsung MagicINFO, to compile a cryptominer directly on a victim's endpoint. The attack began with the installation of a rogue AnyDesk instance after multiple failed attempts, followed by creating a new local admin account and disabling Microsoft Defender. The attacker utilized the Silent XMR Miner Builder to compile the miner, which generated significant EDR telemetry, making the intrusion noticeable. Despite the organization being alerted to the initial compromise, the same endpoint was flagged again for malicious activity shortly thereafter. This incident highlights the importance of monitoring for unusual compiler activity and patching known vulnerabilities promptly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track SilentXMRMiner and CVE-2024-7399 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…