Cybersecurity experts have recently uncovered a sophisticated attack involving a vulnerability in Samsung’s MagicINFO software. This security flaw allowed attackers to infiltrate Windows systems and construct a cryptocurrency miner directly on compromised machines.
Exploiting Samsung’s MagicINFO
The attack, which surfaced in early September 2026, revolved around exploiting a known weakness in MagicINFO Premium, a platform often utilized for managing digital signage. Hackers gained access to the system, subsequently installing a remote access tool and disabling Microsoft Defender.
During the infiltration process, the attackers created an administrative account, enabling them to use the system’s resources to mine Monero. This method left a distinct activity trail, as the miner was assembled on the device rather than being deployed as a pre-built program.
Investigation and Findings
Researchers at Huntress, while examining a managed endpoint, discovered the unusual activity tied to this breach. Their report shared with Cyber Security News (CSN) highlighted how the attackers utilized the system’s own capabilities to compile the miner, triggering conspicuous alerts.
The investigation revealed the entry point was linked to CVE-2025-4632, a vulnerability Samsung addressed in May 2025. Although earlier issues with MagicINFO had been partially resolved, this remaining flaw allowed continued exploitation.
Despite initial mitigation advice, further malicious activity was detected eight days later, emphasizing the persistent threat posed by unresolved vulnerabilities. The attackers attempted multiple times to download AnyDesk, a legitimate remote access tool, finally succeeding and securing their access with a password.
Building and Deploying the Miner
With system defenses weakened, the intruders proceeded to assemble a Monero miner using various Windows development tools and compilers. This process, started from the new user’s Documents folder, was conspicuous due to the burst of compiler activity it generated.
Huntress’s report detailed how the mining operations connected with a public mining pool, utilizing both CPU and potentially GPU resources. This activity was disguised under typical Windows processes, complicating detection efforts.
The case underscores the need for security teams to remain vigilant for unexpected compiler activity and adjustments to antivirus settings. Simply removing the miner does not address the broader security question of how the attackers initially gained entry.
In conclusion, promptly patching internet-facing installations of MagicINFO and monitoring for unauthorized remote access attempts are crucial steps in preventing similar breaches. The persistence of such vulnerabilities highlights the ongoing challenges in maintaining robust cybersecurity defenses.
