The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint
Huntress, Thursday, September 24th, 2026
Huntress found an attacker compiling a cryptominer on a compromised endpoint after exploiting a Samsung MagicINFO flaw and disabling Defender.
Huntress observed a threat actor compiling a cryptominer directly on a victim's endpoint rather than dropping a pre-built binary, tailoring the payload while generating unusually conspicuous EDR telemetry.
The intrusion began with exploitation of a known Samsung MagicINFO vulnerability, after which the attacker deployed a rogue AnyDesk instance on the third attempt, created a new local admin account, and disabled Windows Defender protections.
Huntress says the case shows why defenders should watch for indicators beyond known miner binaries, since repeated RMM download attempts and unexpected compiler activity can reveal a compromise before the final payload runs.