The threat actor responsible for exploiting weak Craft CMS instances has changed its strategy to target misconfigured Docker instances and Magento CMS.
A threat actor known as Mimo (also known as Hezb) has been implicated in the activities. Mimo has a history of using N-day security holes in different online apps to install cryptocurrency miners.
In a report released this week, Datadog Security Labs stated that while Mimo’s main incentive is still financial, the sophistication of their recent operations raises the possibility that they are preparing for more lucrative illegal activities through bandwidth monetization and cryptocurrency mining.
In May 2025, Sekoia disclosed Mimo’s use of CVE-2025-32432, a serious security vulnerability in Craft CMS, for proxyjacking and cryptojacking.
The threat actor’s recently discovered attack chains include exploiting unknown PHP-FPM vulnerabilities in Magento e-commerce installations to gain initial access read more about Threat Actor Mimo Targets Magento and Docker to Deploy Crypto Miners and Proxyware.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
