Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit Samsung Flaw to Install Cryptominer

Hackers Exploit Samsung Flaw to Install Cryptominer

Posted on September 25, 2026 By CWS

Cybersecurity experts have recently uncovered a sophisticated attack involving a vulnerability in Samsung’s MagicINFO software. This security flaw allowed attackers to infiltrate Windows systems and construct a cryptocurrency miner directly on compromised machines.

Exploiting Samsung’s MagicINFO

The attack, which surfaced in early September 2026, revolved around exploiting a known weakness in MagicINFO Premium, a platform often utilized for managing digital signage. Hackers gained access to the system, subsequently installing a remote access tool and disabling Microsoft Defender.

During the infiltration process, the attackers created an administrative account, enabling them to use the system’s resources to mine Monero. This method left a distinct activity trail, as the miner was assembled on the device rather than being deployed as a pre-built program.

Investigation and Findings

Researchers at Huntress, while examining a managed endpoint, discovered the unusual activity tied to this breach. Their report shared with Cyber Security News (CSN) highlighted how the attackers utilized the system’s own capabilities to compile the miner, triggering conspicuous alerts.

The investigation revealed the entry point was linked to CVE-2025-4632, a vulnerability Samsung addressed in May 2025. Although earlier issues with MagicINFO had been partially resolved, this remaining flaw allowed continued exploitation.

Despite initial mitigation advice, further malicious activity was detected eight days later, emphasizing the persistent threat posed by unresolved vulnerabilities. The attackers attempted multiple times to download AnyDesk, a legitimate remote access tool, finally succeeding and securing their access with a password.

Building and Deploying the Miner

With system defenses weakened, the intruders proceeded to assemble a Monero miner using various Windows development tools and compilers. This process, started from the new user’s Documents folder, was conspicuous due to the burst of compiler activity it generated.

Huntress’s report detailed how the mining operations connected with a public mining pool, utilizing both CPU and potentially GPU resources. This activity was disguised under typical Windows processes, complicating detection efforts.

The case underscores the need for security teams to remain vigilant for unexpected compiler activity and adjustments to antivirus settings. Simply removing the miner does not address the broader security question of how the attackers initially gained entry.

In conclusion, promptly patching internet-facing installations of MagicINFO and monitoring for unauthorized remote access attempts are crucial steps in preventing similar breaches. The persistence of such vulnerabilities highlights the ongoing challenges in maintaining robust cybersecurity defenses.

Cyber Security News Tags:Cryptominer, cyber attack, Cybersecurity, endpoint security, MagicINFO flaw, Microsoft Defender, Monero mining, remote access tools, Samsung security, Vulnerability

Post navigation

Previous Post: Linux Kernel Vulnerability Allows Root Access and Container Escape
Next Post: AI-Driven Botnet Targets Unsecured Docker Servers

Related Posts

Critical Red Hat ACM Flaw Allows Cluster-Admin Access Critical Red Hat ACM Flaw Allows Cluster-Admin Access Cyber Security News
TeamViewer DEX Vulnerabilities Let Attackers Trigger DoS Attack and Expose Sensitive Data TeamViewer DEX Vulnerabilities Let Attackers Trigger DoS Attack and Expose Sensitive Data Cyber Security News
New QR Code Attack Via PDFs Evades Detection Systems and Harvest Credentials New QR Code Attack Via PDFs Evades Detection Systems and Harvest Credentials Cyber Security News
Top 20 APM Tools to Enhance Application Performance Top 20 APM Tools to Enhance Application Performance Cyber Security News
Auditing Data Access Controls for Privacy Regulation Adherence Auditing Data Access Controls for Privacy Regulation Adherence Cyber Security News
Innovative Phishing Tactics Exploit Blob URLs and Microsoft Teams Innovative Phishing Tactics Exploit Blob URLs and Microsoft Teams Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • TWEAKOS Malware Exploits Telegram for Account Theft
  • Salmon Launches EVI to Secure AI and Autonomous Systems
  • Sauron Loader Malware Evades Detection with New Tactics
  • AI-Driven Botnet Targets Unsecured Docker Servers
  • Hackers Exploit Samsung Flaw to Install Cryptominer

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • TWEAKOS Malware Exploits Telegram for Account Theft
  • Salmon Launches EVI to Secure AI and Autonomous Systems
  • Sauron Loader Malware Evades Detection with New Tactics
  • AI-Driven Botnet Targets Unsecured Docker Servers
  • Hackers Exploit Samsung Flaw to Install Cryptominer

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark