
Huntress Finds Threat Actor Compiling Silent XMR Miner Directly on Endpoint
Huntress says a threat actor exploited Samsung MagicINFO, installed AnyDesk, and compiled a SilentXMRMiner build on the endpoint, producing noisy compiler telemetry before the miner reached C3Pool.
Ava Okello, DetectionLondon2 min read
LONDON - Huntress said on September 24, 2026, that a threat actor compiled a Monero miner directly on a victim endpoint instead of dropping a finished binary. Principal Threat Intelligence Analyst Harlan Carvey wrote that the activity followed exploitation of Samsung MagicINFO and produced unusually conspicuous endpoint telemetry.
The report says the intrusion began early in September 2026 on a managed endpoint running Samsung MagicINFO Premium, digital signage software. Huntress associated the activity with CVE-2025-4632, which lets an attacker write an arbitrary file with system authority. Samsung fixed that bug in May 2025 after an earlier flaw, CVE-2024-7399, was found to have an incomplete fix. Huntress said the customer was told how to remediate, and eight days later the same endpoint was reported again for different post-compromise activity tied to the same access path. Figures in the report show tomcat9.exe as the parent, which Huntress noted because MagicINFO runs as a Java application on embedded Apache Tomcat. Those figures are timestamped September 11, 2026.
Huntress said the actor needed three attempts to download AnyDesk from 194.87.89.30 on port 8899. Microsoft Defender removed a certutil.exe download and a later PowerShell Invoke-WebRequest attempt. A third download succeeded. The actor then set an AnyDesk password, created a local administrator account named oldadministrator, and disabled Microsoft Defender through SystemSettingsAdminFlows.exe. The published indicator table lists that download address, the new account name, a password shared by the account and AnyDesk, and SHA256 0d202e16408770e8b6cceb14e1e3e72946b154bf881d27fe33d0060315b30dd1 for a file named x.exe.


After Defender was disabled, telemetry showed Silent XMR Miner Builder.exe running from the new user's Documents folder. Huntress said the builder is commonly associated with the open-source SilentXMRMiner project. Child processes included the .NET Framework utilities csc.exe and cvtres.exe, then C compilers including donut.exe, tcc.exe, and MinGW64 cc1.exe and gcc.exe. Huntress described Donut as position-independent code for in-memory execution of scripts, executables, DLLs, and .NET assemblies, and tcc.exe as the Tiny C compiler. The compilers ran as children of the unsigned builder and produced a spike in activity before a miner binary appeared.


The resulting miner connected to the public pool C3Pool to mine Monero, using the host CPU and potentially the GPU. Huntress said it ran under explorer.exe with mining arguments, including algorithm rx/0 and pool auto.c3pool.org on port 19999, with the wallet user redacted in the report. Huntress noted that legitimate Windows Explorer does not take those arguments, so the command line itself is a detection. For detection engineering teams, the earlier signals are repeated remote-access-tool downloads from an internet-facing MagicINFO host, a new local admin, Defender tampering through SystemSettingsAdminFlows.exe, and a burst of csc.exe, cvtres.exe, and C compilers under an unsigned builder. Huntress's recommendations are to patch internet-facing MagicINFO, treat repeated remote-access-tool downloads as compromise, and alert on unusual compiler activity rather than only on known miner binaries.
Sources:
Ava Okello covers detection engineering and alert operations for SOCtember from London.
Related stories
Detection
AI Tool Adoption Floods SOCs With Alert Noise, Not Agent Takeovers
Detection
Report Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust Them
Detection
Untuned Alerts Can Hide Active Intrusions From the SOC
Response