logo

The Sharp Taste of Mimo'lette: Mimo Targets Craft CMS

ID: 57e61c7c-217c-58f7-9a2f-c0589885fccd

STIX ID: report--57e61c7c-217c-58f7-9a2f-c0589885fccd

Feed Name: Sekoia.com

Threat Score
78/100

Date Published: 2025-05-27

Date Updated: 2026-07-20

...
...

This report documents active exploitation of Craft CMS CVE-2025-32432 by the Mimo (Hezb) intrusion set to install a webshell and deploy a Go-based loader ('4l4md4r') that installs an XMRig Monero miner and IPRoyal residential proxyware; it includes attack-chain analysis, IoCs (file hashes, URLs, wallets), operator attribution to online personas, and suggested detection opportunities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.