Samsung MagicINFO flaw used to compile a Monero miner
Huntress says attackers exploited Samsung MagicINFO CVE-2025-4632 on one Windows host to install AnyDesk and compile a Monero miner.
Huntress documented one managed Windows endpoint where a threat actor exploited Samsung MagicINFO CVE-2025-4632, an arbitrary file-write flaw that can grant SYSTEM privileges. Samsung fixed the flaw in May 2025; Cyber Security News says that fix followed an incomplete patch of CVE-2024-7399. The actor obtained AnyDesk through certutil and PowerShell, created the local administrator account 'oldadministrator', and disabled Microsoft Defender. Cyber Security News says Defender blocked two download attempts before AnyDesk was installed, while the Huntress account names the certutil and PowerShell downloads without giving that count. An unsigned Silent XMR Miner Builder then called csc.exe, donut.exe, tcc.exe, and MinGW64 to compile a Monero miner that ran under explorer.exe with injected mining arguments and connected to C3Pool. Both sources describe a single endpoint rather than a measured campaign, and Cyber Security News says Huntress urges patching internet-facing MagicINFO servers.
- Initial access used Samsung MagicINFO CVE-2025-4632, an arbitrary file write as SYSTEM, which Samsung fixed in May 2025.
- Cyber Security News says CVE-2025-4632 followed an incomplete fix of CVE-2024-7399.
- Huntress observed one managed Windows endpoint, not a measured multi-organization campaign.
- Attackers used certutil and PowerShell to obtain AnyDesk; Cyber Security News says Defender blocked two download attempts before installation.
- The actor created local administrator account 'oldadministrator' and disabled Microsoft Defender.
- An unsigned Silent XMR Miner Builder invoked csc.exe, donut.exe, tcc.exe, and MinGW64 to compile a Monero miner on the host.
- The miner ran under explorer.exe with injected mining arguments and connected to C3Pool.
- Cyber Security News says Huntress urges patching internet-facing MagicINFO servers.
Coverage timelineoldest first · each row is one article
- · 2d agoThe Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint
Huntress· 48
Huntress details attackers exploiting Samsung MagicINFO CVE-2025-4632 to install AnyDesk and compile an XMR cryptominer directly on the endpoint.
- · 1d agoHackers Used a Samsung Flaw to Build a Cryptominer Inside Victim Systems
Cyber Security News· 58
Huntress says attackers used Samsung MagicINFO CVE-2025-4632 on one Windows host to compile a Monero miner.
Vulnerabilities in this storyAll →
- CVE-2024-73999.892%Unauthenticated Path Traversal File Write in Samsung MagicINFO 9 Serverpublished · Samsung MagicINFO 9 Server KEV