The Sharp Taste of Mimo'lette: Mimo Targets Craft CMS
ID: 57e61c7c-217c-58f7-9a2f-c0589885fccd
STIX ID: report--57e61c7c-217c-58f7-9a2f-c0589885fccd
Feed Name: Sekoia.com
Threat Score
This report documents active exploitation of Craft CMS CVE-2025-32432 by the Mimo (Hezb) intrusion set to install a webshell and deploy a Go-based loader ('4l4md4r') that installs an XMRig Monero miner and IPRoyal residential proxyware; it includes attack-chain analysis, IoCs (file hashes, URLs, wallets), operator attribution to online personas, and suggested detection opportunities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
