Mimo Exploits Craft CMS RCE to Deploy Cryptominer and Proxyware in Coordinated Campaign (Campaign)
ID: baeaa8cc-5af0-5735-9365-46bee77144ea
STIX ID: report--baeaa8cc-5af0-5735-9365-46bee77144ea
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-05-27
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Between February and May 2025 the Mimo intrusion set actively exploited CVE-2025-32432 in Craft CMS to inject a PHP webshell and trigger a multi-stage infection that deployed a Go loader, XMRig cryptominer and IPRoyal residential proxyware; operators used LD_PRELOAD hijacking (alamdar.so), process-killing to remove competitors, and left multiple IOCs and attribution clues tying activity to Mimo and potential Ottoman/Turkish-linked operators, with financial motives and ties to Minus ransomware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
