Post-Exploitation Activities Observed from the Samsung MagicINFO 9 Server Flaw
ID: d5e254d6-5eb6-5bac-bbcc-030a147612a0
STIX ID: report--d5e254d6-5eb6-5bac-bbcc-030a147612a0
Feed Name: Huntress Blog
Huntress observed limited in-the-wild exploitation of a Samsung MagicINFO 9 Server vulnerability (affecting versions including 21.1050.0 and 21.1040.2) after a public PoC was released. In three incidents attackers used scripted commands to download executables (srvany.exe renamed as php-cli/php-fpm), attempted to install them as services for persistence, and ran reconnaissance commands; the report includes Windows Event log evidence, EDR execution traces, timelines, and IOCs (URLs, file paths, hashes), and recommends not exposing MagicINFO servers to the internet until a patch is available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
