SOC Prime Bias: High

29 Sep 2026 14:05 UTC

The Not-So-Silent Miner: Endpoint-Based Cryptominer Compilation

Author Photo
SOC Prime Team linkedin icon Follow
The Not-So-Silent Miner: Endpoint-Based Cryptominer Compilation
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

A threat actor exploited a Samsung MagicINFO vulnerability to gain initial access to a managed endpoint. Rather than deploying a pre-built binary, the attacker compiled a custom Monero cryptominer directly on the compromised host using multiple C compilers and .NET utilities. This approach enabled environment-specific optimization but also produced highly visible EDR telemetry because of the sudden increase in compilation activity.

Investigation

Huntress researchers identified the intrusion through unusual EDR telemetry associated with a Samsung MagicINFO installation. The investigation traced the activity to an Apache Tomcat service (tomcat9.exe) executing commands to download AnyDesk through certutil and PowerShell. Analysts also observed the attacker creating a local administrator account, disabling Windows Defender, and running several compilers to build the cryptominer.

Mitigation

Organizations should promptly patch all internet-facing Samsung MagicINFO deployments to address known vulnerabilities. Defenders should monitor for repeated Remote Access Tool (RMM) download attempts and unexpected compiler execution on endpoints. Limiting public internet exposure of digital signage management software can further reduce the attack surface.

Response

When suspicious compiler activity or unauthorized RMM downloads are detected, isolate the affected endpoint immediately to prevent additional payload execution. Conduct a full forensic investigation to determine the initial access vector, including vulnerable web services. Review local user accounts for unauthorized additions and verify the integrity of security controls such as Microsoft Defender.

Attack Flow

We are still updating this part.

Detections

Download or Upload via Powershell (via cmdline)

SOC Prime Team
28 Sep 2026

Possible Hidden AnyDesk Install (via cmdline)

SOC Prime Team
28 Sep 2026

Possible Account for Persistence [Windows] (via cmdline)

SOC Prime Team
28 Sep 2026

Short File Name (via cmdline)

SOC Prime Team
28 Sep 2026

Using Certutil for Data Encoding and Cert Operations (via cmdline)

SOC Prime Team
28 Sep 2026

Alternative Remote Access / Management Software (via process_creation)

SOC Prime Team
28 Sep 2026

Suspicious File Download Direct IP (via proxy)

SOC Prime Team
28 Sep 2026

IOCs (HashSha256) to detect: The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint

SOC Prime AI Rules
28 Sep 2026

IOCs (SourceIP) to detect: The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint

SOC Prime AI Rules
28 Sep 2026

IOCs (DestinationIP) to detect: The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint

SOC Prime AI Rules
28 Sep 2026

Detection of New Admin Account Creation and Disabling of Defender [Microsoft Windows Security Event Log]

SOC Prime AI Rules
28 Sep 2026

Suspicious Use of Certutil or PowerShell for AnyDesk Download [Windows Process Creation]

SOC Prime AI Rules
28 Sep 2026

Simulation Execution

  • Attack Narrative & Commands: The adversary has gained initial access and seeks to ensure long-term persistence and prevent detection. The attacker first creates a local user named oldadministrator and adds them to the local Administrators group. To prevent Windows Defender from flagging their subsequent tool downloads, the attacker invokes SystemSettingsAdminFlows.exe with the disable argument. This specific sequence is designed to mimic a known pattern used by certain cryptomining malware families to weaken host defenses.

  • Regression Test Script:

    # Simulation Script: Trigger 'oldadministrator' and Defender Disable detection
    # Note: This script must be run with Administrative privileges
    
    Write-Host "[+] Starting Simulation..." -ForegroundColor Cyan
    
    # 1. Create the specific user name required by the detection rule
    Write-Host "[+] Creating account: oldadministrator" -ForegroundColor Yellow
    net user oldadministrator Password123! /add
    net localgroup administrators oldadministrator /add
    
    # 2. Simulate the disabling of Defender via SystemSettingsAdminFlows.exe
    # We use the specific command line pattern the rule is looking for
    Write-Host "[+] Executing SystemSettingsAdminFlows.exe with 'disable' argument" -ForegroundColor Yellow
    Start-Process "C:WindowsSystem32SystemSettingsAdminFlows.exe" -ArgumentList "disable" -ErrorAction SilentlyContinue
    
    Write-Host "[+] Simulation complete. Check SIEM for alerts." -ForegroundColor Green
  • Cleanup Commands:

    # Cleanup Script: Remove simulated artifacts
    Write-Host "[+] Cleaning up simulation artifacts..." -ForegroundColor Cyan
    
    # Remove the created user
    net user oldadministrator /delete
    
    # Note: We do not 're-enable' defender via script to avoid altering system state 
    # unless specifically required for the test environment stability.