Critical Samsung Flaw Lets Attackers Install Cryptominers
Key Takeaways Attackers exploited a known vulnerability in Samsung’s MagicINFO software (CVE-2025-4632) to gain unauthorized access to a Windows system. Instead of deploying a pre-compiled...
Key Takeaways
- Attackers exploited a known vulnerability in Samsung’s MagicINFO software (CVE-2025-4632) to gain unauthorized access to a Windows system.
- Instead of deploying a pre-compiled cryptominer, the threat actors used the compromised system’s resources to compile a Monero miner on-site.
- The attackers installed a remote access tool (AnyDesk), created a new administrator account, and disabled Microsoft Defender to ensure persistent access and hinder detection.
- The on-system compilation process, while unusual, created distinct alerts that could serve as early warning signs for defenders.
- Samsung released a patch for CVE-2025-4632 in May 2025, addressing a previously incomplete fix for CVE-2024-7399.
Cybersecurity researchers have uncovered a sophisticated attack where threat actors leveraged a previously identified critical flaw in Samsung’s MagicINFO software to breach a Windows system. Once inside, the attackers did not simply drop a pre-fabricated cryptocurrency miner. Instead, they uniquely utilized the victim’s own computing power to compile a Monero cryptominer directly on the compromised machine, leaving behind a trail of unusual system activities.
Table Of Content
The incident, first detected in early September 2026, targeted a system running MagicINFO Premium, Samsung’s digital signage management solution. Following the initial breach, the attackers proceeded to install a remote access tool, establish a new administrator account, and disable Microsoft Defender before initiating Monero mining operations, effectively hijacking the system’s processing capabilities for their illicit gains.
Exploiting a Samsung Vulnerability
Analysts at Huntress, who identified this activity during an investigation of a managed endpoint, detailed their findings in a comprehensive report. According to Huntress said in a report, the intruders compiled the miner directly on the victim’s system, an action that generated noticeable security alerts. This approach, documented in a detailed analysis, highlights how a known vulnerability can lead to sustained access and the unauthorized commandeering of valuable computing resources.
The entry point was traced back to CVE-2025-4632, a vulnerability within MagicINFO that allows an attacker to write files with system-level privileges. Samsung had issued a fix for this flaw in May 2025, which itself was a response to an incomplete patch for an earlier MagicINFO issue, CVE-2024-7399. The critical nature of this file writing vulnerability meant that internet-facing MagicINFO installations required immediate patching to prevent exploitation.
Despite initial remediation advice provided to the affected customer, investigators observed renewed malicious activity originating from the same access vector merely eight days later. This recurrence underscored that the vulnerable service remained accessible to the attackers, enabling them to re-establish control. The report focuses on a single affected endpoint, but the implications extend to any unpatched MagicINFO installations.
The attackers made multiple attempts to download AnyDesk, a legitimate remote access program, for unauthorized use. Their initial two attempts, utilizing a Windows download utility and PowerShell respectively, were successfully blocked by Microsoft Defender. However, a third attempt proved successful, allowing the attackers to set a password for persistent remote access.
Subsequent process analysis confirmed that the remote access tool’s installation was directly linked to the compromised MagicINFO service. This chain of events demonstrated how a seemingly benign administrative tool could be weaponized by intruders. To further solidify their control and evade detection, the attackers created a local administrator account with the same password used for AnyDesk and subsequently disabled Microsoft Defender via a standard Windows settings component.
On-System Miner Compilation and Detection
With system defenses weakened, the attackers launched a Monero miner builder from the newly created administrator’s Documents folder. This builder initiated several Windows development utilities and C compilers as child processes. Compiling the miner on the victim’s machine likely allowed the attackers to tailor the executable for optimal performance on that specific system architecture.
This method, however, introduced a significant operational security challenge for the attackers. The miner builder was unsigned, and the sudden surge of compiler activity on the endpoint was highly anomalous and stood out in monitoring logs. Huntress emphasized that this unusual compilation process presented a crucial opportunity for defenders to detect and thwart the attack before the fully compiled miner could even begin its operations, especially since the final miner executable might not have had a known signature.
Following the successful compilation, investigators observed the miner connecting to a public mining pool, presumably utilizing the host’s CPU and potentially its GPU. The discovery of mining options appearing inappropriately under the Windows Explorer process indicated that malicious code had been injected into this critical system process. This further underscores the importance for security teams to focus on behavioral analysis rather than solely relying on signatures for known executables.
What You Should Do
- Immediately apply all available patches for Samsung MagicINFO installations, especially those exposed to the internet. Specifically, ensure updates addressing CVE-2025-4632 and CVE-2024-7399 are installed.
- Monitor for unusual activity related to remote access tools. Repeated attempts to download or install legitimate remote access software (like AnyDesk) should be treated as potential intrusion attempts, even if initially blocked.
- Implement robust endpoint detection and response (EDR) solutions to detect anomalous process behavior, such as unexpected compiler activity or the launch of development utilities in unusual directories.
- Actively monitor for any changes to antivirus or endpoint security settings, particularly attempts to disable security features like Microsoft Defender.
- Beyond simply removing identified malware, conduct a thorough forensic investigation to determine the initial compromise vector and ensure all backdoors or persistent access mechanisms are eliminated.
- Regularly review and audit local administrator accounts for any unauthorized additions or modifications.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.