Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal. Detection, Dallas. Ava Okello: Report Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust Them.

SOCtember

Always First. Fast SOC News.

Huntress process tree showing a PowerShell download of AnyDesk under tomcat9.exe.
Huntress. AnyDesk download attempt under tomcat9.exe.

Detection

Huntress Finds Threat Actor Compiling Silent XMR Miner Directly on Endpoint

Huntress says a threat actor exploited Samsung MagicINFO, installed AnyDesk, and compiled a SilentXMRMiner build on the endpoint, producing noisy compiler telemetry before the miner reached C3Pool.

Ava Okello, DetectionLondon2 min read

LONDON - Huntress said on September 24, 2026, that a threat actor compiled a Monero miner directly on a victim endpoint instead of dropping a finished binary. Principal Threat Intelligence Analyst Harlan Carvey wrote that the activity followed exploitation of Samsung MagicINFO and produced unusually conspicuous endpoint telemetry.

The report says the intrusion began early in September 2026 on a managed endpoint running Samsung MagicINFO Premium, digital signage software. Huntress associated the activity with CVE-2025-4632, which lets an attacker write an arbitrary file with system authority. Samsung fixed that bug in May 2025 after an earlier flaw, CVE-2024-7399, was found to have an incomplete fix. Huntress said the customer was told how to remediate, and eight days later the same endpoint was reported again for different post-compromise activity tied to the same access path. Figures in the report show tomcat9.exe as the parent, which Huntress noted because MagicINFO runs as a Java application on embedded Apache Tomcat. Those figures are timestamped September 11, 2026.

Huntress said the actor needed three attempts to download AnyDesk from 194.87.89.30 on port 8899. Microsoft Defender removed a certutil.exe download and a later PowerShell Invoke-WebRequest attempt. A third download succeeded. The actor then set an AnyDesk password, created a local administrator account named oldadministrator, and disabled Microsoft Defender through SystemSettingsAdminFlows.exe. The published indicator table lists that download address, the new account name, a password shared by the account and AnyDesk, and SHA256 0d202e16408770e8b6cceb14e1e3e72946b154bf881d27fe33d0060315b30dd1 for a file named x.exe.

Huntress telemetry showing SystemSettingsAdminFlows.exe disabling Defender for user oldadministrator.
Huntress. Defender tamper via SystemSettingsAdminFlows.exe.The new local account oldadministrator is named in the same figure.
Huntress telemetry of the command that created the local account oldadministrator.
Huntress. Local account creation from the MagicINFO process chain.The new administrator account is oldadministrator.

After Defender was disabled, telemetry showed Silent XMR Miner Builder.exe running from the new user's Documents folder. Huntress said the builder is commonly associated with the open-source SilentXMRMiner project. Child processes included the .NET Framework utilities csc.exe and cvtres.exe, then C compilers including donut.exe, tcc.exe, and MinGW64 cc1.exe and gcc.exe. Huntress described Donut as position-independent code for in-memory execution of scripts, executables, DLLs, and .NET assemblies, and tcc.exe as the Tiny C compiler. The compilers ran as children of the unsigned builder and produced a spike in activity before a miner binary appeared.

SilentXMRMiner project features page, as reproduced in the Huntress report.
Huntress. SilentXMRMiner features shown in the report.The builder Huntress tied to the open-source SilentXMRMiner project.
Huntress detection of unsigned x.exe under the oldadministrator Documents folder.
Huntress. Resulting miner executable x.exe.SHA256 in the figure matches the hash Huntress published for x.exe.

The resulting miner connected to the public pool C3Pool to mine Monero, using the host CPU and potentially the GPU. Huntress said it ran under explorer.exe with mining arguments, including algorithm rx/0 and pool auto.c3pool.org on port 19999, with the wallet user redacted in the report. Huntress noted that legitimate Windows Explorer does not take those arguments, so the command line itself is a detection. For detection engineering teams, the earlier signals are repeated remote-access-tool downloads from an internet-facing MagicINFO host, a new local admin, Defender tampering through SystemSettingsAdminFlows.exe, and a burst of csc.exe, cvtres.exe, and C compilers under an unsigned builder. Huntress's recommendations are to patch internet-facing MagicINFO, treat repeated remote-access-tool downloads as compromise, and alert on unusual compiler activity rather than only on known miner binaries.

Sources:


Ava Okello covers detection engineering and alert operations for SOCtember from London.

Related stories

Detection desk