Attackers build “silent” cryptominer on victim’s machine and give themselves away
Brief
Security researchers at Huntress have uncovered an unusual attack in which a threat actor compiled a cryptocurrency miner directly on a victim’s computer, rather than simply dropping a ready-made one, and in doing so generated so much activity that the intrusion stood out.
The incident began in early September 2026 with the exploitation of CVE-2025-4632, a vulnerability in Samsung MagicINFO, the content management software used to run digital signage. The flaw, which lets an attacker write arbitrary files with system-level privileges, was fixed in May 2025 after an earlier bug (CVE-2024-7399) whose fix proved incomplete.
Despite the organisation being alerted to the initial compromise and advised on remediation, the same endpoint was flagged again eight days later for fresh malicious activity tied to the same access route.
