logo

Mimo Targets Magento, Docker, and Cloud Environments (Campaign)

ID: 6950ccb2-c1f3-5b3f-b8a9-e3a58f817191

STIX ID: report--6950ccb2-c1f3-5b3f-b8a9-e3a58f817191

Feed Name: Wiz Cloud Threat Landscape

Threat Score
75/100

Date Published: 2025-07-21

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

The report summarizes a Mimo threat actor campaign that leverages PHP-FPM vulnerabilities in Magento and misconfigured Docker APIs to deploy 4l4md4r loaders/stagers and an alamdar.so rootkit via /etc/ld.so.preload, uses memfd_create for in-memory payload execution, and monetizes infections through XMRig cryptojacking and IPRoyal proxyjacking while self-propagating across networks and targeting cloud instances (including AWS EC2).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.