logo

The Sharp Taste of Mimo’lette: Analyzing Mimo’s Latest Campaign targeting Craft CMS

ID: fc4000ae-1da1-5810-8a6e-4171b981f226

STIX ID: report--fc4000ae-1da1-5810-8a6e-4171b981f226

Feed Name: Sekoia.io Blog

Threat Score
75/100

Date Published: 2025-05-27

Date Updated: 2026-04-29

Author: Jeremy Scion, Pierre Le Bourhis and Sekoia TDR

...
...

This report details active in-the-wild exploitation of CVE-2025-32432 against Craft CMS leading to webshell installation and execution of an infection script that deploys a Go-based loader (4l4md4r/alamdar), XMRig cryptominer, and IPRoyal residential proxyware; it attributes activity to the Mimo/Hezb intrusion set, provides IoCs (hashes, URLs, wallet, email), and discusses detection opportunities and operator identifiers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.