The Sharp Taste of Mimo'lette: Analyzing Mimo's Latest Campaign targeting Craft CMS

May 28, 2025, 1:14 p.m.

Description

Between February and May, multiple exploitations of CVE-2025-32432, a Remote Code Execution vulnerability in Craft CMS, were observed. The attack chain involves deploying a webshell, downloading an infection script, and executing malicious payloads including a loader, crypto miner, and residential proxyware. The Mimo intrusion set is believed responsible, using distinctive identifiers like '4l4md4r' and 'n1tr0'. The group deploys XMRig for cryptomining and IPRoyal for bandwidth monetization. Two potential operators, 'EtxArny' and 'N1tr0', were identified through social media analysis. While showing interest in Middle Eastern affairs, the group's primary motivation appears financial. Detection opportunities include monitoring for unusual processes in temporary directories and kernel module alterations.

Date

  • Created: May 27, 2025, 7:02 p.m.
  • Published: May 27, 2025, 7:02 p.m.
  • Modified: May 28, 2025, 1:14 p.m.

Indicators

  • fc04f1ef05847607bce3b0ac3710c80c5ae238dcc7fd842cd15e252c18dd7a62
  • 7868cb82440632cc4fd7a451a351c137a39e1495c84172a17894daf1d108ee9a
  • 3a71680ffb4264e07da4aaca16a3f8831b9a30d444215268e82b2125a98b94aa
  • 2e46816450ad1b4baa85e2a279031f37608657be93e1095238e2b6c36bbb3fd5
  • 1aa4d88a38f5a27a60cfc6d6995f065da074ee340789ed00ddc29abc29ea671e
  • 85.106.113.168
  • n1tr0.online
  • windows.n1tro.cyou

Attack Patterns

Additional Informations

  • Lebanon

Linked vulnerabilities