logo

Mimo CoinMiner and Mimus Ransomware Installed via Vulnerability Attacks

ID: 3b67de00-d39f-5286-b0f6-01ce4dd3c7d4

STIX ID: report--3b67de00-d39f-5286-b0f6-01ce4dd3c7d4

Feed Name: ASEC

Threat Score
75/100

Date Published: 2024-01-18

Date Updated: 2026-04-26

Author: Sanseo

...
...

**Executive summary:** ASEC observed the Mimo (Hezb) threat actor actively exploiting multiple known RCE vulnerabilities across widely used services (Log4Shell, Confluence, WSO2, PaperCut, ActiveMQ) to install XMRig coinminers, Mimus ransomware (based on MauriCrypt), proxyware, and an NHAS reverse SSH backdoor; the report provides detailed TTPs, IoCs (download URLs, MD5s, wallet/C2 addresses, email), detection names, and remediation guidance to patch vulnerable services and block infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.