A threat actor compromised a managed endpoint by exploiting CVE-2025-4632, an arbitrary-file-write vulnerability in Samsung MagicINFO Premium that executes with SYSTEM privileges. The actor attempted repeatedly to download and install AnyDesk from 194.87.89[.]30, created a local account named oldadministrator, and disabled Microsoft Defender to establish and retain access.
The intruder then used Silent XMR Miner Builder.exe to compile a Monero cryptominer directly on the compromised system, generating .NET utility and C-compiler activity that can provide defenders with detectable telemetry. The completed miner connected to the C3Pool mining service and consumed the endpoint’s CPU—and potentially GPU—for Monero mining, demonstrating continued abuse of a publicly exposed vulnerability despite an available patch.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
The actor ran Silent XMR Miner Builder.exe from the new user's Documents folder, spawning .NET and C compilation tools to build a cryptominer directly on the compromised host. The resulting executable connected to auto.c3pool.org:19999 and used the RandomX rx/0 algorithm to mine Monero using the host's CPU and potentially GPU.
The threat actor used SystemSettingsAdminFlows.exe to disable Microsoft Defender after Defender had detected and remediated earlier AnyDesk download attempts.
After the compromise, the actor repeatedly attempted to download AnyDesk from 194.87.89[.]30:8899, eventually installing it and configuring a password. The actor also created a local account named oldadministrator, using the same password for that account and AnyDesk.
In early September 2026, a threat actor compromised a managed endpoint by exploiting CVE-2025-4632 in Samsung MagicINFO Premium. Malicious commands executed through tomcat9.exe linked the activity to the MagicINFO access vector.
Samsung fixed CVE-2025-4632 in MagicINFO Premium after determining that the prior fix for CVE-2024-7399 was incomplete. The vulnerability could allow arbitrary file writes with SYSTEM authority.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.