Threat Advisory

Samsung MagicINFO Flaw Enables Arbitrary File Write as System Authority

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A threat actor exploited a Samsung MagicINFO vulnerability to gain system-level access, deploy AnyDesk for remote access, create a local administrator account, disable Microsoft Defender, and compile a Monero cryptominer directly on the compromised endpoint. The activity generated significant compiler and EDR telemetry, providing detection opportunities before the miner was deployed.

CVE-2025-4632: A Samsung MagicINFO vulnerability enabling attackers to write an arbitrary file with SYSTEM-level privileges was exploited as the initial access vector in the observed attack.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A threat actor exploited a Samsung MagicINFO vulnerability to gain system-level access, deploy AnyDesk for remote access, create a local administrator account, disable Microsoft Defender, and compile a Monero cryptominer directly on the compromised endpoint. The activity generated significant compiler and EDR telemetry, providing detection opportunities before the miner was deployed.

CVE-2025-4632: A Samsung MagicINFO vulnerability enabling attackers to write an arbitrary file with SYSTEM-level privileges was exploited as the initial access vector in the observed attack.[emaillocker id="1283"]

The threat actor subsequently used AnyDesk for persistence, created a new local administrator account, disabled Microsoft Defender, and used the Silent XMR Miner Builder along with multiple .NET and C compilers to build a Monero cryptominer directly on the endpoint.

The resulting miner connected to C3Pool and used the compromised system's CPU and potentially GPU resources for cryptocurrency mining. Unusual compiler activity, repeated RMM downloads, new administrator accounts, and abnormal mining parameters executed through `explorer.exe` provide useful detection opportunities.

RECOMMENDATION:

We recommend you to update Samsung MagicINFO to the latest available version.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1190 Exploit Public Facing Application-
Execution T1059.001 Command and Scripting Interpreter PowerShell
Execution T1059.003 Command and Scripting Interpreter Windows Command Shell
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1036.005 Masquerading Match Legitimate Resource Name or Location
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu