International Cyber Expo International Cyber Expo
  • About Us
Friday, 25 September, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Attackers build “silent” cryptominer on victim’s machine and give themselves away

Huntress researchers say the intruder exploited an unpatched Samsung MagicINFO digital signage server before compiling mining malware directly on the compromised endpoint

by Guru Writer
September 25, 2026
in News
Attackers build “silent” cryptominer on victim’s machine and give themselves away
Share on FacebookShare on Twitter

Security researchers at Huntress have uncovered an unusual attack in which a threat actor compiled a cryptocurrency miner directly on a victim’s computer, rather than simply dropping a ready-made one, and in doing so generated so much activity that the intrusion stood out.

The incident began in early September 2026 with the exploitation of CVE-2025-4632, a vulnerability in Samsung MagicINFO, the content management software used to run digital signage. The flaw, which lets an attacker write arbitrary files with system-level privileges, was fixed in May 2025 after an earlier bug (CVE-2024-7399) whose fix proved incomplete.

Despite the organisation being alerted to the initial compromise and advised on remediation, the same endpoint was flagged again eight days later for fresh malicious activity tied to the same access route.

Third time lucky

According to Huntress, the attacker made three attempts to download the AnyDesk remote access tool. Microsoft Defender blocked the first two attempts, which used the Windows utility certutil and PowerShell, respectively. The third succeeded.

Once AnyDesk was installed, the attacker set a password for it, created a new local administrator account named “oldadministrator” using the same password, and then disabled Microsoft Defender.

Anything but silent

With defences switched off, the attacker ran “Silent XMR Miner Builder”, a tool likely derived from the open-source SilentXMRMiner project, which builds miners for the Monero cryptocurrency. The builder launched a series of .NET utilities and C compilers on the machine to produce the final miner, which then connected to the public C3Pool mining pool while disguised as the Windows Explorer process.

Huntress noted that compiling a miner on the endpoint could let an attacker tailor it to the target machine, for example by optimising for its processor. Ironically, however, the burst of compiler activity from an unsigned program created conspicuous telemetry for defenders to spot.

While cryptominers are a common sight in incidents, the researchers described on-endpoint compilation as an outlier. They stressed that the miner itself is not the real threat: what matters is how the attacker got in.

Recommendations

Huntress advises organisations to patch internet-facing Samsung MagicINFO deployments promptly, treat repeated attempts to download remote access tools as a sign of compromise, and monitor for unexpected compiler activity rather than relying solely on detecting known mining binaries.

Legitimate Windows Explorer processes should never run with cryptocurrency mining arguments, the researchers added, making such command lines a useful detection opportunity.

The full analysis, including indicators of compromise, is available on the Huntress blog: https://www.huntress.com/blog/threat-actor-compiles-cryptominer

ShareTweet
Previous Post

OpenAI agent breached Australia’s Medicare portal – and nobody noticed for three months

Recent News

Attackers build “silent” cryptominer on victim’s machine and give themselves away

Attackers build “silent” cryptominer on victim’s machine and give themselves away

September 25, 2026
OpenAI agent breached Australia’s Medicare portal – and nobody noticed for three months

OpenAI agent breached Australia’s Medicare portal – and nobody noticed for three months

September 24, 2026
Zero-day hackers ditch exploits for a fake image file in new DarkMe campaign

Zero-day hackers ditch exploits for a fake image file in new DarkMe campaign

September 23, 2026
CRA Reporting Is Live: What Manufacturers, Vendors, and Distributors Need to Know

CRA Reporting Is Live: What Manufacturers, Vendors, and Distributors Need to Know

September 23, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol