MalwareSep 25, 2026
Attackers build “silent” cryptominer on victim’s machine and give themselves away
Attackers compiled a cryptominer on victim machines, leading to noticeable activity.
Summary
Huntress researchers discovered an unusual attack where threat actors compiled a cryptocurrency miner directly on victim machines. This process generated significant activity, inadvertently revealing the intrusion. The attack chain began in early September 2026 with the exploitation of CVE-2025-4632.
Indicators of Compromise
- cve — CVE-2025-4632
Entities
cryptocurrency miner (product)Huntress (vendor)