The Sharp Taste of Mimo’lette: Analyzing Mimo’s Latest Campaign targeting Craft CMS
ID: fc4000ae-1da1-5810-8a6e-4171b981f226
STIX ID: report--fc4000ae-1da1-5810-8a6e-4171b981f226
Feed Name: Sekoia.io Blog
Date Published: 2025-05-27
Date Updated: 2026-04-29
Author: Jeremy Scion, Pierre Le Bourhis and Sekoia TDR
This report details active in-the-wild exploitation of CVE-2025-32432 against Craft CMS leading to webshell installation and execution of an infection script that deploys a Go-based loader (4l4md4r/alamdar), XMRig cryptominer, and IPRoyal residential proxyware; it attributes activity to the Mimo/Hezb intrusion set, provides IoCs (hashes, URLs, wallet, email), and discusses detection opportunities and operator identifiers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
