Vulnerabilities
MagicINFO flaw used to build a Monero miner on the host
Attackers used CVE-2025-4632 in Samsung MagicINFO to install AnyDesk, kill Defender and compile a Monero miner on the server. How it ran and what to check.
Huntress has described an intrusion in early September 2026 that started with CVE-2025-4632, a file-write flaw in Samsung MagicINFO 9 Server rated CVSS 9.8. The attacker installed AnyDesk, created a local administrator, switched off Microsoft Defender and then built a Monero cryptominer on the server itself, compiling it from source with tools the builder brought along. Eight days after Huntress reported the first incident, the same endpoint raised new alerts through the same entry point.
If you run MagicINFO to manage Samsung digital signage, check the version today. The flaw was fixed in release 21.1052 in May 2025 and CISA added it to its Known Exploited Vulnerabilities (KEV) catalog on May 22, 2025. Signage servers are often installed by an integrator and left off the patch schedule, so a flaw fixed 16 months ago can still give an attacker SYSTEM today.
How the flaw works
MagicINFO is a Java web application that runs on Apache Tomcat and pushes content to Samsung displays. One of its servlets, /MagicInfo/servlet/SWUpdateFileUploader, accepts file uploads for software updates. In vulnerable builds it does not check whether the caller is logged in, does not check the file extension, and joins the fileName parameter straight onto a path on disk.
That last point is the path traversal. A file name containing ../ sequences climbs out of the upload folder, so an attacker can write a JavaServer Pages (JSP) file into the web root under /MagicInfo/. Requesting that JSP runs it inside Tomcat, and because the service runs with SYSTEM rights on Windows, so does every command the web shell executes.
Samsung first tried to fix this in August 2024 as CVE-2024-7399, in release 21.1050. A public proof of concept followed on April 30, 2025, and Arctic Wolf and the SANS Internet Storm Center saw exploitation within days, including Mirai botnet variants. Huntress then confirmed that 21.1050.0 was still exploitable. CVE-2025-4632 is the bypass of that fix, and 21.1052 is the release that closes it.
What the attacker did
In the September case, Huntress traced the malicious commands to tomcat9.exe, the MagicINFO web server process. The first goal was remote access that did not depend on the bug. The attacker tried to pull AnyDesk from 194.87.89[.]30 on port 8899, first with certutil.exe -urlcache and then with PowerShell Invoke-WebRequest. Defender blocked both. The third attempt worked.
With AnyDesk in place, the attacker set an AnyDesk password, created a local administrator account called oldadministrator with the same password, and disabled Defender through SystemSettingsAdminFlows.exe, a signed Windows binary that backs parts of the Settings app.
Next came Silent XMR Miner Builder.exe, run from the Documents folder of the new account. It is the Windows builder from the open-source SilentXMRMiner project. Instead of dropping a ready-made miner, it compiles one on the spot, and it spawned a chain of compilers to do it:
csc.exeandcvtres.exe, the .NET C# compiler and resource converterdonut.exe, which turns executables and .NET assemblies into position-independent shellcodetcc.exe, the Tiny C Compilergcc.exeandcc1.exefrom MinGW64
The resulting miner used the RandomX rx/0 algorithm, connected to auto.c3pool.org:19999 and ran under the name explorer.exe. Its command line gave it away: arguments such as --algo="rx/0", --url=auto.c3pool.org:19999 and --cpu-max-threads-hint=100 do not belong to the Windows shell.
A freshly compiled binary has a hash no antivirus vendor has seen. The cost is noise: Huntress reports that the build caused a sharp spike in endpoint telemetry. A signage server has no reason to run a C compiler, so those processes make a reliable alert.
What to do
1. Upgrade
Upgrade MagicINFO 9 Server to 21.1052 or later. Builds before 21.1052 are vulnerable to CVE-2025-4632, and 21.1050 only covers the older CVE-2024-7399. If you find a MagicINFO install you did not know about, it almost certainly has not been patched either.
2. If you cannot upgrade today
Take the MagicINFO web interface off the internet. Allow it only from the networks where the displays and the administrators sit, at the host firewall or the upstream firewall. At the reverse proxy or web application firewall, block requests to /MagicInfo/servlet/SWUpdateFileUploader from anywhere else. This reduces exposure; it does not fix the flaw.
3. Check whether you were hit
- Process creation logs (Sysmon event ID 1 or Windows Security event 4688) with
tomcat9.exeas the parent ofcmd.exe,powershell.exeorcertutil.exe. - AnyDesk installed on the server, and outbound connections to
194.87.89[.]30orauto.c3pool.org. - A local account named
oldadministrator, or any administrator you cannot account for.net localgroup administratorslists them. - Defender switched off.
Get-MpComputerStatusin PowerShell shows whether real-time protection is enabled. csc.exe,donut.exe,tcc.exe,gcc.exeorcc1.exerunning on a server that never builds software.- An
explorer.exeprocess with mining arguments in its command line, or sustained CPU use near 100%. - Unexpected
.jspfiles under the MagicINFO web root, which would point to a web shell left by the original exploit.
4. If you find any of it
Removing the miner alone leaves the way in open, which is why the Huntress case came back eight days later. Rebuild the server on 21.1052 or later, remove AnyDesk and the rogue account, and rotate every credential the machine held: local admin passwords, service accounts, and any domain account that has logged on to it. Then look at what else that server could reach, since the attacker had SYSTEM rights and an interactive remote session.
The wider lesson
Signage, building management and meeting-room servers rarely make it into the patch schedule, because nobody thinks of them as servers. They still run Windows and Tomcat, still face the internet when an integrator set them up that way, and still give an attacker SYSTEM. Put them in the asset inventory, and alert on development tools running on hosts that have no reason to compile code.
Our attack surface management work finds forgotten internet-facing systems like MagicINFO consoles, and our security operations team builds the process-creation detections described above. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.
Sources: Huntress: The Not So Silent Miner, Cyber Press, First Hackers News, Cybersecurity News, Censys advisory on CVE-2025-4632, Huntress: Samsung MagicINFO 9 Server flaw, BleepingComputer, Help Net Security.