logo

Post-Exploitation Activities Observed from the Samsung MagicINFO 9 Server Flaw

ID: d5e254d6-5eb6-5bac-bbcc-030a147612a0

STIX ID: report--d5e254d6-5eb6-5bac-bbcc-030a147612a0

Feed Name: Huntress Blog

Threat Score
60/100

Date Published: 2025-05-09

Date Updated: 2026-04-28

...
...

Huntress observed limited in-the-wild exploitation of a Samsung MagicINFO 9 Server vulnerability (affecting versions including 21.1050.0 and 21.1040.2) after a public PoC was released. In three incidents attackers used scripted commands to download executables (srvany.exe renamed as php-cli/php-fpm), attempted to install them as services for persistence, and ran reconnaissance commands; the report includes Windows Event log evidence, EDR execution traces, timelines, and IOCs (URLs, file paths, hashes), and recommends not exposing MagicINFO servers to the internet until a patch is available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.