Huntress researchers documented active exploitation of a vulnerability in Samsung MagicINFO 9 Server (version 21.1050.0), a digital signage content management system. Three separate incidents were observed across customer environments. Two coordinated attacks used identical scripted commands to download executables from a remote staging server, install a persistent Windows service disguised as 'PHP5.3.8', and establish a backdoor. The third incident appeared to be reconnaissance only. Attackers used srvany.exe (renamed to php-cli.exe) to run a secondary payload as a Windows service. Indicators of compromise are provided, including the attacker's staging IP (185.225.226.53) and dropped file paths. No patch is currently available; the recommendation is to ensure MagicINFO servers are not internet-facing.

5m read timeFrom huntress.com
Post cover image