[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fmKzGB8SKxo2nYiUDQ4WafSZLHTX5ZU-m9ijjUPARTdc":3},{"article":4,"iocs":40},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":11,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":23,"category":24,"article_tags":27},"2580ca9a-c961-4d2d-8ebf-b9705c3774e4","Attackers build “silent” cryptominer on victim’s machine and give themselves away","attackers-build-silent-cryptominer-on-victim-s-machine-and-give-themselves-away-6c7610","Security researchers at Huntress have uncovered an unusual attack in which a threat actor compiled a cryptocurrency miner directly on a victim’s computer, rather than simply dropping a ready-made one, and in doing so generated so much activity that the intrusion stood out. The incident began in early September 2026 with the exploitation of CVE-2025-4632, […] The post Attackers build “silent” cryptominer on victim’s machine and give themselves away appeared first on IT Security Guru.","Huntress researchers discovered an unusual attack where threat actors compiled a cryptocurrency miner directly on victim machines. This process generated significant activity, inadvertently revealing the intrusion. The attack chain began in early September 2026 with the exploitation of CVE-2025-4632.","Attackers compiled a cryptominer on victim machines, leading to noticeable activity.",null,"https:\u002F\u002Fwww.itsecurityguru.org\u002F2026\u002F09\u002F25\u002Fattackers-build-silent-cryptominer-on-victims-machine-and-give-themselves-away\u002F?utm_source=rss&utm_medium=rss&utm_campaign=attackers-build-silent-cryptominer-on-victims-machine-and-give-themselves-away","2026-09-25T12:20:43+00:00","2026-09-25T14:00:13.849015+00:00",7,[17,20],{"name":18,"type":19},"cryptocurrency miner","product",{"name":21,"type":22},"Huntress","vendor","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":23,"icon":11,"name":25,"slug":26},"Malware","malware",[28,33,35],{"category":29},{"id":30,"icon":11,"name":31,"slug":32},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":34},{"id":23,"icon":11,"name":25,"slug":26},{"category":36},{"id":37,"icon":11,"name":38,"slug":39},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[41],{"type":42,"value":43,"context":44},"cve","CVE-2025-4632","Vulnerability exploited to initiate the attack"]