Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Local AI Model Modifies Credential Dumper to Bypass EDR Detection
September 26, 2026
F-Droid 2.0 Released: Major Redesign Improves Open-Source Android App Discovery
September 26, 2026
OpenAI Agents Autonomously Attempt Website Exploits
September 26, 2026
Home/Threats/Critical Samsung Flaw Lets Attackers Install Cryptominers
Threats

Critical Samsung Flaw Lets Attackers Install Cryptominers

Key Takeaways Attackers exploited a known vulnerability in Samsung’s MagicINFO software (CVE-2025-4632) to gain unauthorized access to a Windows system. Instead of deploying a pre-compiled...

Sarah simpson
Sarah simpson
September 25, 2026 4 Min Read
15 0

Key Takeaways

  • Attackers exploited a known vulnerability in Samsung’s MagicINFO software (CVE-2025-4632) to gain unauthorized access to a Windows system.
  • Instead of deploying a pre-compiled cryptominer, the threat actors used the compromised system’s resources to compile a Monero miner on-site.
  • The attackers installed a remote access tool (AnyDesk), created a new administrator account, and disabled Microsoft Defender to ensure persistent access and hinder detection.
  • The on-system compilation process, while unusual, created distinct alerts that could serve as early warning signs for defenders.
  • Samsung released a patch for CVE-2025-4632 in May 2025, addressing a previously incomplete fix for CVE-2024-7399.

Cybersecurity researchers have uncovered a sophisticated attack where threat actors leveraged a previously identified critical flaw in Samsung’s MagicINFO software to breach a Windows system. Once inside, the attackers did not simply drop a pre-fabricated cryptocurrency miner. Instead, they uniquely utilized the victim’s own computing power to compile a Monero cryptominer directly on the compromised machine, leaving behind a trail of unusual system activities.

Table Of Content

  • Key Takeaways
  • Exploiting a Samsung Vulnerability
  • On-System Miner Compilation and Detection
  • What You Should Do

The incident, first detected in early September 2026, targeted a system running MagicINFO Premium, Samsung’s digital signage management solution. Following the initial breach, the attackers proceeded to install a remote access tool, establish a new administrator account, and disable Microsoft Defender before initiating Monero mining operations, effectively hijacking the system’s processing capabilities for their illicit gains.

Exploiting a Samsung Vulnerability

Analysts at Huntress, who identified this activity during an investigation of a managed endpoint, detailed their findings in a comprehensive report. According to Huntress said in a report, the intruders compiled the miner directly on the victim’s system, an action that generated noticeable security alerts. This approach, documented in a detailed analysis, highlights how a known vulnerability can lead to sustained access and the unauthorized commandeering of valuable computing resources.

The entry point was traced back to CVE-2025-4632, a vulnerability within MagicINFO that allows an attacker to write files with system-level privileges. Samsung had issued a fix for this flaw in May 2025, which itself was a response to an incomplete patch for an earlier MagicINFO issue, CVE-2024-7399. The critical nature of this file writing vulnerability meant that internet-facing MagicINFO installations required immediate patching to prevent exploitation.

Despite initial remediation advice provided to the affected customer, investigators observed renewed malicious activity originating from the same access vector merely eight days later. This recurrence underscored that the vulnerable service remained accessible to the attackers, enabling them to re-establish control. The report focuses on a single affected endpoint, but the implications extend to any unpatched MagicINFO installations.

The attackers made multiple attempts to download AnyDesk, a legitimate remote access program, for unauthorized use. Their initial two attempts, utilizing a Windows download utility and PowerShell respectively, were successfully blocked by Microsoft Defender. However, a third attempt proved successful, allowing the attackers to set a password for persistent remote access.

Subsequent process analysis confirmed that the remote access tool’s installation was directly linked to the compromised MagicINFO service. This chain of events demonstrated how a seemingly benign administrative tool could be weaponized by intruders. To further solidify their control and evade detection, the attackers created a local administrator account with the same password used for AnyDesk and subsequently disabled Microsoft Defender via a standard Windows settings component.

On-System Miner Compilation and Detection

With system defenses weakened, the attackers launched a Monero miner builder from the newly created administrator’s Documents folder. This builder initiated several Windows development utilities and C compilers as child processes. Compiling the miner on the victim’s machine likely allowed the attackers to tailor the executable for optimal performance on that specific system architecture.

This method, however, introduced a significant operational security challenge for the attackers. The miner builder was unsigned, and the sudden surge of compiler activity on the endpoint was highly anomalous and stood out in monitoring logs. Huntress emphasized that this unusual compilation process presented a crucial opportunity for defenders to detect and thwart the attack before the fully compiled miner could even begin its operations, especially since the final miner executable might not have had a known signature.

Following the successful compilation, investigators observed the miner connecting to a public mining pool, presumably utilizing the host’s CPU and potentially its GPU. The discovery of mining options appearing inappropriately under the Windows Explorer process indicated that malicious code had been injected into this critical system process. This further underscores the importance for security teams to focus on behavioral analysis rather than solely relying on signatures for known executables.

What You Should Do

  • Immediately apply all available patches for Samsung MagicINFO installations, especially those exposed to the internet. Specifically, ensure updates addressing CVE-2025-4632 and CVE-2024-7399 are installed.
  • Monitor for unusual activity related to remote access tools. Repeated attempts to download or install legitimate remote access software (like AnyDesk) should be treated as potential intrusion attempts, even if initially blocked.
  • Implement robust endpoint detection and response (EDR) solutions to detect anomalous process behavior, such as unexpected compiler activity or the launch of development utilities in unusual directories.
  • Actively monitor for any changes to antivirus or endpoint security settings, particularly attempts to disable security features like Microsoft Defender.
  • Beyond simply removing identified malware, conduct a thorough forensic investigation to determine the initial compromise vector and ensure all backdoors or persistent access mechanisms are eliminated.
  • Regularly review and audit local administrator accounts for any unauthorized additions or modifications.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEHackerPatchSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

TWEAKOS Malware Transforms Telegram into Stealer, C2, and Stolen Account Marketplace

Next Post

AI-Powered Botnet “DarkGate” Found Operating Inside Compromised Servers

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Linux Kernel Flaw (CVE-2024-0001) Lets Local Users Gain Root, Escape Containers
September 25, 2026
AI-Powered Botnet “DarkGate” Found Operating Inside Compromised Servers
September 25, 2026
Critical Samsung Flaw Lets Attackers Install Cryptominers
September 25, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us