Back to Feed
MalwareSep 25, 2026

Attackers build “silent” cryptominer on victim’s machine and give themselves away

Attackers compiled a cryptominer on victim machines, leading to noticeable activity.

Summary

Huntress researchers discovered an unusual attack where threat actors compiled a cryptocurrency miner directly on victim machines. This process generated significant activity, inadvertently revealing the intrusion. The attack chain began in early September 2026 with the exploitation of CVE-2025-4632.

Indicators of Compromise

  • cve — CVE-2025-4632

Entities

cryptocurrency miner (product)Huntress (vendor)