A threat actor exploited a Samsung MagicINFO vulnerability to gain system-level access, deploy AnyDesk for remote access, create a local administrator account, disable Microsoft Defender, and compile a Monero cryptominer directly on the compromised endpoint. The activity generated significant compiler and EDR telemetry, providing detection opportunities before the miner was deployed.
CVE-2025-4632: A Samsung MagicINFO vulnerability enabling attackers to write an arbitrary file with SYSTEM-level privileges was exploited as the initial access vector in the observed attack.[/subscribe_to_unlock_form]
A threat actor exploited a Samsung MagicINFO vulnerability to gain system-level access, deploy AnyDesk for remote access, create a local administrator account, disable Microsoft Defender, and compile a Monero cryptominer directly on the compromised endpoint. The activity generated significant compiler and EDR telemetry, providing detection opportunities before the miner was deployed.
CVE-2025-4632: A Samsung MagicINFO vulnerability enabling attackers to write an arbitrary file with SYSTEM-level privileges was exploited as the initial access vector in the observed attack.[emaillocker id="1283"]
The threat actor subsequently used AnyDesk for persistence, created a new local administrator account, disabled Microsoft Defender, and used the Silent XMR Miner Builder along with multiple .NET and C compilers to build a Monero cryptominer directly on the endpoint.
The resulting miner connected to C3Pool and used the compromised system's CPU and potentially GPU resources for cryptocurrency mining. Unusual compiler activity, repeated RMM downloads, new administrator accounts, and abnormal mining parameters executed through `explorer.exe` provide useful detection opportunities.
We recommend you to update Samsung MagicINFO to the latest available version.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1190 | Exploit Public | Facing Application- |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Execution | T1059.003 | Command and Scripting Interpreter | Windows Command Shell |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
The following reports contain further technical details:
[/emaillocker]