Samsung MagicINFO Exploit Leads to Persistent Access and On-Host Cryptominer Build
Attackers exploited a known Samsung MagicINFO file-write flaw, installed AnyDesk, created an administrator account and disabled Microsoft Defender before building a Monero miner on the victim. The case shows why removing a payload is insufficient when the exposed service remains unpatched. The post Samsung MagicINFO Exploit Leads to Persistent Access and On-Host Cryptominer Build appeared first on Secure Bulletin.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.