Mimo is a financially motivated Linux malware operation and associated malware cluster active since at least 2022, primarily known for exploiting internet-facing vulnerabilities to deploy illicit monetization payloads. It has been observed targeting vulnerable server-side applications, including Craft CMS, where exploitation of CVE-2025-32432 enabled unauthenticated remote code execution through a multi-stage chain involving a PHP webshell, a shell-script stager, and a Go-based loader. The loader then deployed XMRig for Monero cryptomining and IPRoyal residential proxyware to monetize victim bandwidth in parallel.
Mimo’s tooling emphasizes resource hijacking, operational resilience, and removal of competing malware. Observed infection scripts checked for prior compromise, terminated rival miners and proxyware, searched for writable execution locations, and used LD_PRELOAD hijacking with a malicious shared library to conceal malicious processes from process listings. The loader also attempted privilege escalation and modified system behavior to support stealth and continued execution. These behaviors indicate a mature monetization-focused intrusion set rather than a single standalone binary.
The malware ecosystem associated with Mimo includes a Go-based loader, cryptomining payloads, proxyware, and historically ransomware deployment. Reporting has linked the intrusion set to Minus ransomware in addition to repeated XMRig deployment, suggesting diversification beyond pure cryptojacking. Mimo has also been referenced in earlier exploitation activity following Log4Shell against VMware Horizon, where Mimu/Mimo miner bots appeared alongside other payloads such as Sliver and remote-access tooling, although those broader campaigns included multiple actors and toolsets.
Mimo is commonly associated with the alias Hezb and recurring operator-linked identifiers such as 4l4md4r and alamdar. Available reporting consistently characterizes the operation as primarily financially motivated, with compromised Linux servers used for CPU mining and bandwidth resale. Targeting has centered on exposed enterprise web infrastructure rather than a single vertical, with vulnerable content management and virtualization-adjacent systems appearing in observed campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Unlike your typical fairytale villain, Mimo didn’t leave glass slippers—just suspicious payloads... including a loader, a crypto miner and a residential proxyware.
“Jin bots were tied to use of Sliver, and used the same wallets as Mimo… Mimo miner bot… we found… Mimo miner bot executables.”
2 distinct techniques documented for this family, organized by ATT&CK tactic.
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mimo is an intrusion-set-associated malware cluster/campaign centered on exploiting public-facing vulnerabilities to deploy a Golang loader, XMRig cryptomining payloads, and IPRoyal residential proxyware for monetization. The report also links Mimo to deployment of Minus Ransomware in some campaigns.
Mimo is a malware family involved in cryptomining and proxyware campaigns, exploiting CVE-2025-32432.
Mimo is a threat actor and malware loader that exploits web application vulnerabilities to deploy cryptominers (XMRig) and proxyware (IPRoyal) for financial gain. It uses advanced evasion techniques such as LD_PRELOAD hijacking and process-killing routines to maintain persistence and maximize resource hijacking. Mimo has also diversified into ransomware operations.
Miner bot referenced as deploying XMRig-based Monero mining; shares wallets/infrastructure with Jin and is installed via PowerShell/batch tooling after Horizon exploitation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.