HomeCyber BalkansAttackers Create Stealthy Cryptominer on Victim's Machine and Reveal Themselves

Attackers Create Stealthy Cryptominer on Victim’s Machine and Reveal Themselves

Published on

spot_img

Security researchers from Huntress have recently unveiled a peculiar cybersecurity attack that has raised alarm bells in the tech community. In a departure from the common practice of deploying ready-made malware, a threat actor opted to compile a cryptocurrency miner directly on the victim’s computer. This choice resulted in an unusually high level of system activity, which ultimately made the breach more detectable.

The situation first unfolded in early September 2026 when the attacker exploited a vulnerability, identified as CVE-2025-4632, within Samsung MagicINFO—the content management software responsible for operating digital signage. This particular flaw enables unauthorized individuals to write arbitrary files under system-level privileges. It’s noteworthy that this vulnerability had previously been addressed in May 2025 following an incomplete fix of a prior bug, known as CVE-2024-7399.

Despite the affected organization being notified about the initial compromise and receiving guidance on remedial actions, the same endpoint triggered alarms just eight days later due to renewed malicious activities associated with the same exploitation path. This persistence in exploiting the same entry point underscores a more profound issue in cybersecurity practices, where initial alerts do not lead to effective remediation.

Huntress investigators shared that the attacker made three separate attempts to download the AnyDesk remote access tool—an application that allows remote control over an endpoint. The first two attempts were thwarted by Microsoft Defender; the initial attempt employed the Windows utility certutil, while the second leveraged PowerShell. However, the third attempt proved successful, allowing the attacker to gain unfettered access.

With AnyDesk successfully installed, the perpetrator proceeded to set a password for it. Furthermore, they created a new local administrator account named “oldadministrator” that shared the same password, effectively granting themselves elevated privileges on the compromised machine. In a significant escalation, the attacker disabled Microsoft Defender, dismantling the very defenses that were meant to protect the system.

Once the defenses were disabled, the attacker ran a tool named “Silent XMR Miner Builder.” This tool is believed to be derived from the open-source project, SilentXMRMiner, which specializes in constructing miners for the Monero cryptocurrency. The builder initiated several .NET utilities and C compilers, leading to the production of the cryptocurrency miner, which then connected to the public C3Pool mining pool while masquerading as a legitimate Windows Explorer process.

The researchers at Huntress highlighted that compiling the miner directly on the victim’s endpoint could provide the attacker with specific optimizations tailored for the target machine’s processor. Ironically, the extensive compiler activity generated from an unsigned program became a glaring telemetry signal that was easy for security teams to detect. While such incidents involving cryptominers are not rare, the method of on-endpoint compilation stands out as an anomaly in the landscape of cybersecurity threats.

Huntress researchers emphasized that the actual miner isn’t the primary concern; rather, the focus should be on the methods the attacker employed to gain initial access. This highlights the importance of understanding the entry points exploited in cybersecurity incidents, as they often open doors to more significant threats.

To combat such threats, Huntress recommends that organizations promptly patch their internet-facing installations of Samsung MagicINFO. They also advise treating repeated attempts to download remote access tools as potential indicators of compromise. Moreover, monitoring unexpected compiler activity is crucial, as relying solely on known mining binaries may not be adequate for detecting sophisticated threats.

Legitimate Windows Explorer processes should never be executing cryptocurrency mining commands, making these specific command lines potential red flags for detection efforts. By emphasizing proactive measures and focusing on the underlying causes of such intrusions, organizations can bolster their defenses against similar attacks in the future.

For a more comprehensive analysis, including details on indicators of compromise, readers can access Huntress’s full report on their blog. The significance of this incident extends beyond its technical specifics, serving as a crucial reminder of the evolving landscape of cybersecurity threats and the need for vigilant defenses against increasingly creative attack methodologies.

Source link

Latest articles

Vulnerabilities in Salesforce Agentforce Increase AI Agent Risks

Zenity Labs Unveils Serious Zero-Click Vulnerabilities in Salesforce Agentforce In a pivotal disclosure, security researchers...

Live Webinar on Securing the Industrial Edge: Navigating and Mastering OT Cybersecurity in Manufacturing

Profile of James Young: A Leader in Cybersecurity at Google Cloud Security James Young, a...

OpenAI Agent Breached Australian Health Service

Security Breach of an Australian Health Service Raises Concerns Over AI Safety A serious security...

RemControl Banking Trojan Provides Attackers with Remote Access to Android Devices

Rising Threat: New Android Banking Trojan Named RemControl Recent findings from cybersecurity experts at Group-IB...

More like this

Vulnerabilities in Salesforce Agentforce Increase AI Agent Risks

Zenity Labs Unveils Serious Zero-Click Vulnerabilities in Salesforce Agentforce In a pivotal disclosure, security researchers...

Live Webinar on Securing the Industrial Edge: Navigating and Mastering OT Cybersecurity in Manufacturing

Profile of James Young: A Leader in Cybersecurity at Google Cloud Security James Young, a...

OpenAI Agent Breached Australian Health Service

Security Breach of an Australian Health Service Raises Concerns Over AI Safety A serious security...