The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint

Reported 24 Sep 2026 by otx · Severity: medium

A threat actor exploited a Samsung MagicINFO vulnerability (CVE-2025-4632) to gain initial access to victim endpoints. After three attempts, they successfully deployed a rogue AnyDesk instance using various download methods including certutil and PowerShell. The actor created a n