The Not-So-Silent Miner: Endpoint-Based Cryptominer Compilation
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
A threat actor exploited a Samsung MagicINFO vulnerability to gain initial access to a managed endpoint. Rather than deploying a pre-built binary, the attacker compiled a custom Monero cryptominer directly on the compromised host using multiple C compilers and .NET utilities. This approach enabled environment-specific optimization but also produced highly visible EDR telemetry because of the sudden increase in compilation activity.
Investigation
Huntress researchers identified the intrusion through unusual EDR telemetry associated with a Samsung MagicINFO installation. The investigation traced the activity to an Apache Tomcat service (tomcat9.exe) executing commands to download AnyDesk through certutil and PowerShell. Analysts also observed the attacker creating a local administrator account, disabling Windows Defender, and running several compilers to build the cryptominer.
Mitigation
Organizations should promptly patch all internet-facing Samsung MagicINFO deployments to address known vulnerabilities. Defenders should monitor for repeated Remote Access Tool (RMM) download attempts and unexpected compiler execution on endpoints. Limiting public internet exposure of digital signage management software can further reduce the attack surface.
Response
When suspicious compiler activity or unauthorized RMM downloads are detected, isolate the affected endpoint immediately to prevent additional payload execution. Conduct a full forensic investigation to determine the initial access vector, including vulnerable web services. Review local user accounts for unauthorized additions and verify the integrity of security controls such as Microsoft Defender.
Attack Flow
We are still updating this part.
Detections
Download or Upload via Powershell (via cmdline)
Possible Hidden AnyDesk Install (via cmdline)
Possible Account for Persistence [Windows] (via cmdline)
Short File Name (via cmdline)
Using Certutil for Data Encoding and Cert Operations (via cmdline)
Alternative Remote Access / Management Software (via process_creation)
Suspicious File Download Direct IP (via proxy)
IOCs (HashSha256) to detect: The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint
IOCs (SourceIP) to detect: The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint
IOCs (DestinationIP) to detect: The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint
Detection of New Admin Account Creation and Disabling of Defender [Microsoft Windows Security Event Log]
Suspicious Use of Certutil or PowerShell for AnyDesk Download [Windows Process Creation]
Simulation Execution
-
Attack Narrative & Commands: The adversary has gained initial access and seeks to ensure long-term persistence and prevent detection. The attacker first creates a local user named
oldadministratorand adds them to the local Administrators group. To prevent Windows Defender from flagging their subsequent tool downloads, the attacker invokesSystemSettingsAdminFlows.exewith thedisableargument. This specific sequence is designed to mimic a known pattern used by certain cryptomining malware families to weaken host defenses. -
Regression Test Script:
# Simulation Script: Trigger 'oldadministrator' and Defender Disable detection # Note: This script must be run with Administrative privileges Write-Host "[+] Starting Simulation..." -ForegroundColor Cyan # 1. Create the specific user name required by the detection rule Write-Host "[+] Creating account: oldadministrator" -ForegroundColor Yellow net user oldadministrator Password123! /add net localgroup administrators oldadministrator /add # 2. Simulate the disabling of Defender via SystemSettingsAdminFlows.exe # We use the specific command line pattern the rule is looking for Write-Host "[+] Executing SystemSettingsAdminFlows.exe with 'disable' argument" -ForegroundColor Yellow Start-Process "C:WindowsSystem32SystemSettingsAdminFlows.exe" -ArgumentList "disable" -ErrorAction SilentlyContinue Write-Host "[+] Simulation complete. Check SIEM for alerts." -ForegroundColor Green -
Cleanup Commands:
# Cleanup Script: Remove simulated artifacts Write-Host "[+] Cleaning up simulation artifacts..." -ForegroundColor Cyan # Remove the created user net user oldadministrator /delete # Note: We do not 're-enable' defender via script to avoid altering system state # unless specifically required for the test environment stability.