Mimo, also known as Hezb, is a financially motivated intrusion set active since at least 2022 that is primarily associated with opportunistic exploitation of internet-facing vulnerabilities to monetize compromised systems. The group is best known for deploying XMRig cryptominers and residential proxyware, and has also been linked to ransomware activity involving the Go-based Minus ransomware and later use of the Go-based 4L4MD4r ransomware. Its operations indicate a pragmatic revenue-driven model centered on cryptojacking, bandwidth monetization, and, at times, ransomware deployment. Mimo has repeatedly exploited N-day and recently disclosed vulnerabilities in public-facing applications, including CMS platforms and Microsoft SharePoint, to gain unauthenticated remote code execution. In observed Craft CMS intrusions, the actor used a multi-stage infection chain that began with server-side code execution and webshell deployment, followed by retrieval of shell scripts and Golang loaders that installed a miner and IPRoyal proxyware. The actor also used LD_PRELOAD-based userland rootkit techniques to hide malicious processes, cleared or replaced competing persistence mechanisms, and killed rival miners and proxyware to maximize monetization of victim resources. The group demonstrates post-compromise tradecraft focused on persistence, defense evasion, and resource control rather than deep bespoke espionage. Reported behaviors include command execution through webshells, deployment of loaders and shared libraries, process hiding, privilege-seeking behavior, and removal of competing malware. Mimo has also been observed expanding its vulnerability targeting across CMS ecosystems, suggesting ongoing reconnaissance and rapid weaponization of newly disclosed flaws. Attribution reporting has associated recurring operator identifiers such as Hezb and 4L4MD4r with the cluster. Evidence in the supplied material suggests a likely operator presence in Turkey, but the geographic attribution remains limited. Overall, Mimo is best characterized as a cybercriminal intrusion set focused on financially motivated exploitation of exposed servers for cryptomining, proxy monetization, and occasional ransomware operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated intrusion set active since at least March 2022, primarily exploiting software vulnerabilities to deploy XMRig cryptominers, and in some campaigns deploying Minus Ransomware. In this report it exploited Craft CMS CVE-2025-32432 to deploy a webshell, a loader, XMRig, and IPRoyal residential proxyware.
Observed exploiting CVE-2025-32432 to deploy a cryptocurrency miner and residential proxyware.
Cryptomining/proxyware-focused actor exploiting N-day flaws in web apps (Craft CMS historically; shifting to Magento) and misconfigured Docker to deploy miners and maintain access.
Referenced as a prior cryptojacking campaign associated with similar Linux in-memory execution tradecraft to avoid leaving artifacts on disk.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.