Mimo CoinMiner and Mimus Ransomware Installed via Vulnerability Attacks
ID: 3b67de00-d39f-5286-b0f6-01ce4dd3c7d4
STIX ID: report--3b67de00-d39f-5286-b0f6-01ce4dd3c7d4
Feed Name: ASEC
Threat Score
**Executive summary:** ASEC observed the Mimo (Hezb) threat actor actively exploiting multiple known RCE vulnerabilities across widely used services (Log4Shell, Confluence, WSO2, PaperCut, ActiveMQ) to install XMRig coinminers, Mimus ransomware (based on MauriCrypt), proxyware, and an NHAS reverse SSH backdoor; the report provides detailed TTPs, IoCs (download URLs, MD5s, wallet/C2 addresses, email), detection names, and remediation guidance to patch vulnerable services and block infections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
