The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint

Imported from official source

Cybersecurity Classified by Officially

Huntress recently observed a threat actor doing something unique post-compromise: instead of simply dropping a miner, they compiled one directly on the victim endpoint, tailoring the payload while generating unusually conspicuous EDR telemetry.  

The incident started with exploitation of a known Samsung MagicINFO flaw. Attackers then deployed a rogue AnyDesk instance (after three tries), created a new local admin account, and disabled Defender protections.  

While the miner compilation aspect of this attack is interesting, the incident shows why defenders should look beyond known miner binaries: repeated RMM downloads and unexpected compiler activity can reveal a compromise before the final payload runs.  

Huntress researchers recently came across a unique incident where, after gaining initial access via exploiting a known Samsung MagicINFO vulnerability and installing a rogue AnyDesk instance on the endpoint, among other things, the threat actor aimed to deploy a cryptominer. 

Cryptominers in incidents aren't uncommon, but what raised our eyebrows was that the actor in this incident compiled the cryptominer directly on the endpoint. They ran commands via Silent XMR Miner Builder.exe (a Windows builder for deploying a Monero, or XMR, cryptominer, commonly associated with the open-source SilentXMRMiner project) that executed several .NET Framework utilities and an array of C compilers. 

Compiling a cryptominer in this way on a victim's endpoint could have various advantages for a threat actor, including allowing them to customize based on the target environment (such as optimizing for the endpoint's CPU architecture). However, these processes also resulted in a significant spike in activity and was – ironically – quite noisy from an EDR telemetry perspective.

This is an extract. The publication continues at the source.

Read the original at the source: https://www.huntress.com/blog/threat-actor-compiles-cryptominer

Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Huntress — imported from official source
Official source
https://www.huntress.com/blog/rss.xml RSS
Imported
September 24, 2026 16:00
Versions
1 recorded
Identity
https://www.huntress.com/blog/threat-actor-compiles-cryptominer

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.