logo

Mimo Exploits Craft CMS RCE to Deploy Cryptominer and Proxyware in Coordinated Campaign (Campaign)

ID: baeaa8cc-5af0-5735-9365-46bee77144ea

STIX ID: report--baeaa8cc-5af0-5735-9365-46bee77144ea

Feed Name: Wiz Cloud Threat Landscape

Threat Score
75/100

Date Published: 2025-05-27

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Between February and May 2025 the Mimo intrusion set actively exploited CVE-2025-32432 in Craft CMS to inject a PHP webshell and trigger a multi-stage infection that deployed a Go loader, XMRig cryptominer and IPRoyal residential proxyware; operators used LD_PRELOAD hijacking (alamdar.so), process-killing to remove competitors, and left multiple IOCs and attribution clues tying activity to Mimo and potential Ottoman/Turkish-linked operators, with financial motives and ties to Minus ransomware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.