Hackers are exploiting a vulnerability in the Craft Content Management System (CMS)that allows remote code execution. The group is exploiting the Craft CMS vulnerability and installing a variety of malicious payloads – including a cryptocurrency miner, a loader (Mimo Loader), and residential proxyware.

The vulnerability, which is being exploited, is tracked as CVE-2025-32432 and was recently patched in Craft CMS versions 3.9.15, 4.14.15 and 5.6.17. The vulnerability was discovered in April 2025 by Orange Cyberdefense SensePost but had already been exploited in attacks since February.
In a new report from Sekoia, it is revealed that the attackers used the vulnerability to gain unauthorized access to vulnerable systems and then installed web shells, which allowed them to maintain remote control over the long term.
See also: Firefox 0-Interaction vulnerability allows arbitrary code execution
Web shells are used to retrieve and execute a malicious shell script named “4l4md4r.sh” (via the curl, wget, or even using the Python library urllib2).
“Regarding Python usage, the attacker imports the urllib2 library with the alias fbi. This unusual naming choice may be a deliberate reference – possibly an ironic reference to the US federal agency – and stands out as a distinct coding choice,” said Sekoia researchers Jeremy Scion and Pierre Le Bourhis.
The shell script, developed by the perpetrators, starts by checking the target system for any signs of previous infection or the presence of other crypto miners. It then proceeds to remove competing cryptocurrency mining software, before delivering new malicious payloads and activating an ELF binary named “4l4md4r”.
The executable in question, known as Mimo Loader, modifies “/etc/ld.so.preload”, a file read by the dynamic linker, to hide the presence of the malware process (“alamdar.so”). The ultimate goal of the loader is to deploy the IPRoyal proxyware and the XMRig miner on the compromised host.
See also: GIMP vulnerability allows arbitrary code execution

The activity is attributed to the Mimo group , which appears to have been active since March 2022. The group has previously exploited known vulnerabilities such as Log4Shell (CVE-2021-44228), a Confluence RCE (CVE-2022-26134), and Apache ActiveMQ RCE (CVE-2023-46604).
According to an earlier report by AhnLab, Mimo has also been linked to ransomware attacks (during 2023), leveraging a Goknown as Mimus.
The Turkish origin of the Mimo group
According to new analysis by cybersecurity firm Sekoia, the most recent attempts to exploit the CVE-2025-32432 vulnerability in Craft CMS appear to be originating from a Turkish IP address (“85.106.113[.]168”), reinforcing the assessment that the Mimo threat actor is physically active in Turkey. This assessment is also supported by indications found in open source sources.
See also: Bitwarden: Vulnerability allows uploading of malicious PDFs
Craft CMS: Exploiting vulnerabilities
In February, CISA added another Craft CMS vulnerability to its list of “Known Exploited Vulnerabilities.” This list includes vulnerabilities that are used by malicious hackers to carry out attacks. The CVE-2025-23209 was patched in mid-January with the release of versions 5.5.8 and 4.13.8. It is a high-severity vulnerability that allows remote code execution, affecting Craft installations where the security key has already been compromised.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: thehackernews.com
