#MagicINFO
Samsung MagicINFO flaw lets attackers build a cryptominer in-system via defender disablement & admin access. #Samsung #Security #Cryptomining #MagicINFO #Monero #CVE2025-4632 https://thedailytechfeed.com/exploit-in-samsung-magicinfo-enabled-cryptomining-on-windows-systems/
September 25, 2026 at 2:53 PM
Huntress found an intrusion via Samsung MagicINFO CVE-2025-4632, followed by repeated AnyDesk installs, Defender tampering, and a SilentXMRMiner-based Monero miner compiled on the endpoint and tied to C3Pool. #MagicINFO #AnyDesk #C3Pool
The Not So Silent Miner: Threat Actor Compiles Cryptominer On The Endpoint
Huntress researchers investigated an intrusion that began with exploitation of a Samsung MagicINFO vulnerability, followed by repeated AnyDesk installation attempts, local account creation, and Defender tampering. The attacker then compiled a SilentXMRMiner-based Monero miner directly on the victim endpoint and connected it to C3Pool for mining. #SamsungMagicINFO #AnyDesk #SilentXMRMiner #C3Pool
www.hendryadrian.com
September 24, 2026 at 7:45 PM
@huntress.com
Attackers exploited Samsung MagicINFO, installed AnyDesk, disabled Defender, and compiled a Monero miner.
-
IOCs: 194[.]87[.]89[.]30, auto[.]c3pool[.]org, oldadministrator
-
#CVE-2025-4632 #Cryptominer #ThreatIntel
Endpoint-Compiled Cryptominer
www.huntress.com
September 24, 2026 at 4:21 PM
Samsung MagicINFO Flaw Used to Deploy AnyDesk and Compile Stealthy Cryptominer Payloads https://packetstorm.news/news/view/44128 #news
September 25, 2026 at 8:58 PM
A Mirai botnet is exploiting a 2024 bug in MagicINFO, a Samsung digital signage system: isc.sans.edu/diary/rss/31...

...and GeoVision security cameras: www.akamai.com/blog/securit...
"Mirai" Now Exploits Samsung MagicINFO CMS (CVE-2024-7399) - SANS Internet Storm Center
"Mirai" Now Exploits Samsung MagicINFO CMS (CVE-2024-7399), Author: Johannes Ullrich
isc.sans.edu
May 6, 2025 at 7:07 PM
Is there any evidence that this specific Samsung MagicINFO vulnerability is being used for lateral movement within internal networks, or does the impact appear limited to the initial compromised host?
September 25, 2026 at 10:15 AM
Hackers are exploiting an unauthenticated remote code execution (RCE) vulnerability in the Samsung MagicINFO 9 Server to hijack devices and deploy malware.
Samsung MagicINFO 9 Server RCE flaw now exploited in attacks
Hackers are exploiting an unauthenticated remote code execution (RCE) vulnerability in the Samsung MagicINFO 9 Server to hijack devices and deploy malware.
www.bleepingcomputer.com
May 6, 2025 at 5:10 PM
U.S. CISA adds a Samsung MagicINFO 9 Server flaw to its Known Exploited Vulnerabilities catalog
U.S. CISA adds a Samsung MagicINFO 9 Server flaw to its Known Exploited Vulnerabilities catalog
U.S. CISA adds a Samsung MagicINFO 9 Server vulnerability to its Known Exploited Vulnerabilities catalog. .....
securityaffairs.com
May 22, 2025 at 11:04 PM
One more example:
A vendor declaring a vulnerability "duplicate" and the infosec company going full-disclosure after 90-days :D ssd-disclosure.com/ssd-advisory...
SSD Advisory - Samsung MagicINFO Unauthenticated RCE - SSD Secure Disclosure
Summary MagicINFO exposes an endpoint which: Wrapping all together it is possible to upload a JSP file to execute arbitrary server-side code without having a valid user. Credit An independent security...
ssd-disclosure.com
May 12, 2025 at 2:54 PM
these things are ADHD traps
August 27, 2025 at 6:58 AM
Die US-Behörde CISA warnt vor beobachteten Attacken auf Schwachstellen in SimpleHelp, Samsung MagicINFO und D-Link DIR-823X. #Security
Angriffe auf SimpleHelp, Samsung MagicINFO und D-Link DIR-823X beobachtet
Die US-Behörde CISA warnt vor beobachteten Attacken auf Schwachstellen in SimpleHelp, Samsung MagicINFO und D-Link DIR-823X.
www.heise.de
April 27, 2026 at 7:10 AM
Improperly Patched Samsung MagicINFO Vulnerability Exploited by Botnet
Improperly Patched Samsung MagicINFO Vulnerability Exploited by Botnet
The patches for an exploited Samsung MagicINFO vulnerability are ineffective and a Mirai botnet has started targeting it.
buff.ly
May 8, 2025 at 9:42 PM
SANS Stormcast Tuesday, May 6th: Mirai Exploiting Samsung magicInfo 9; Kali Signing Key Lost;
https://isc.sans.edu/podcastdetail/9438
May 6, 2025 at 3:20 AM
Samsung MagicInfo Server getFileFromMultipartFile Directory Traversal Remote Code Execution Vulnerability
ZDI-24-1128
Samsung MagicInfo Server getFileFromMultipartFile Directory Traversal Remote Code Execution Vulnerability
www.zerodayinitiative.com
August 16, 2024 at 1:31 AM
Samsung MagicINFO flaw exploited days after PoC exploit publication
Samsung MagicINFO flaw exploited days after PoC publication
Threat actors began exploiting a Samsung MagicINFO vulnerability just days after PoC code was published, warns Arctic Wolf researchers.
securityaffairs.com
May 6, 2025 at 6:55 PM
CVE-2024-7399 (unauthenticated RCE in Samsung MagicInfo Server):

www.zerodayinitiative.com/advisories/Z...
ZDI-24-1128
Samsung MagicInfo Server getFileFromMultipartFile Directory Traversal Remote Code Execution Vulnerability
www.zerodayinitiative.com
August 16, 2024 at 1:12 AM
I've confirmed Samsung's MagicINFO 21.1050 is VULNERABLE to the publicly reported POC in the blog below.

ssd-disclosure.com/ssd-advisory...

The media is reporting this as CVE-2024-7399, but if it is then the patch is incomplete. There is currently NO PATCH AVAILABLE!
May 7, 2025 at 7:08 AM
Attackers Target Samsung MagicINFO Server Bug, Patch Now
Attackers Target Samsung MagicINFO Server Bug, Patch Now
CVE-2025-4632, a patch bypass for a Samsung MagicInfo 9 Server vulnerability disclosed last year, has been exploited by threat actors in the wild.
www.darkreading.com
May 15, 2025 at 7:43 PM
CISA KEV: 4 Exploited CVEs — SimpleHelp, Samsung MagicINFO, D-Link — May 8 Deadline | Abhishek Gautam www.abhs.in/blog/cisa-ke...
CISA KEV: 4 Exploited CVEs — SimpleHelp, Samsung MagicINFO, D-Link — May 8 Deadline
CISA added 4 CVEs to KEV on April 24 2026. SimpleHelp CVSS 9.9, Samsung MagicINFO 8.8, D-Link 7.5. DragonForce ransomware and Mirai botnet active exploitation confirmed. Federal deadline May 8.
www.abhs.in
April 26, 2026 at 6:20 AM
Aufgrund von laufenden Attacken sollten Admins Samsung MagicINFO 9 Server zügig auf den aktuellen Stand bringen. #Security
Cyberattacken: Mirai-Botnetz greift Samsung MagicINFO 9 Server an
Aufgrund von laufenden Attacken sollten Admins Samsung MagicINFO 9 Server zügig auf den aktuellen Stand bringen.
www.heise.de
May 7, 2025 at 10:15 AM
Samsung MagicINFO 9 Server RCE flaw now exploited in attacks
Samsung MagicINFO 9 Server RCE flaw now exploited in attacks
Hackers are exploiting an unauthenticated remote code execution (RCE) vulnerability in the Samsung MagicINFO 9 Server to hijack devices and deploy malware.
www.bleepingcomputer.com
May 6, 2025 at 5:30 PM