Beyond Mimo’lette: Tracking Mimo's Expansion to Magento CMS and Docker
ID: 5451e592-3fbd-5b90-8d33-d3711bdfb180
STIX ID: report--5451e592-3fbd-5b90-8d33-d3711bdfb180
Feed Name: Datadog Security Labs
Datadog Security Research attributes a multi-day intrusion campaign to the financially motivated Mimo (Mimo'lette) actor that has expanded from Craft CMS to Magento and exposed Docker Engine API instances. The actor exploits PHP-FPM command injection in a Magento plugin and uses a Go-based loader that deploys a GSocket-backed reverse shell, memfd_create in-memory execution, and an alamdar LD_PRELOAD rootkit to evade detection and persist via cron, systemd, and legacy init methods; victims are monetized through UPX-packed XMRig Monero mining and IPRoyal proxyware. The report includes detailed IoCs (IPs, domains, file hashes), behavioral indicators, disassembly analysis, and recommended mitigations such as auditing /etc/ld.so.preload, blocking C2 infrastructure, and reviewing cron and SSH artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
