Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issues › Volume 342, Issue 4 › IT Vendor News › Huntress

The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint

Huntress, Thursday, September 24th, 2026

Huntress found an attacker compiling a cryptominer on a compromised endpoint after exploiting a Samsung MagicINFO flaw and disabling Defender.

Huntress observed a threat actor compiling a cryptominer directly on a victim's endpoint rather than dropping a pre-built binary, tailoring the payload while generating unusually conspicuous EDR telemetry.

The intrusion began with exploitation of a known Samsung MagicINFO vulnerability, after which the attacker deployed a rogue AnyDesk instance on the third attempt, created a new local admin account, and disabled Windows Defender protections.

Huntress says the case shows why defenders should watch for indicators beyond known miner binaries, since repeated RMM download attempts and unexpected compiler activity can reveal a compromise before the final payload runs.

more →  ·  More from Huntress →