security1 publisher
Threat actor compiled its Monero miner on the victim endpoint after exploiting CVE-2025-4632
Huntress traced a September 2026 intrusion in which the actor compiled a Monero miner on the endpoint, using a MagicINFO flaw Samsung fixed 16 months earlier. The build step is loud in telemetry, but it ran only after Defender had been disabled.
Publishers:huntress.com
Reality
- Evidence66
- Adoption28
- Hype gap+10
- Incentives62
- Confidence58