← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 25, 2026 · 14:34via Cyber Security News

Hackers Used a Samsung Flaw to Build a Cryptominer Inside Victim Systems

Brief

Attackers broke into a Windows system through a known flaw in Samsung’s MagicINFO software, then built a cryptocurrency miner on the compromised machine.

Rather than arriving as a finished program, the miner was assembled there, leaving an unusual activity trail. The case began in early September 2026 with an alert tied to MagicINFO Premium, software used to manage digital signs.

The attackers went on to install a remote access tool, create an administrator account and turn off Microsoft Defender before using the system’s processing power to mine Monero.

Analysts at Huntress identified the activity while investigating a managed endpoint. Huntress said in a report shared with Cyber Security News (CSN) that the intruders used the victim’s own system to compile the miner, a step that produced conspicuous alerts.

Read more on Cyber Security News→