BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Mimo Shifts Tactics: Targets Magento and Docker for Crypto Mining

Mimo Threat Group Expands Attacks to Magento CMS and Docker, Deploying Cryptominers and Proxyware for Financial Gain

  • A threat group known as Mimo is targeting e-commerce systems and cloud services to install cryptocurrency miners and proxyware.
  • The group recently shifted its attacks from Craft CMS to exploiting Magento CMS and unsecured Docker instances.
  • Mimo uses advanced tactics, such as command injection vulnerabilities and memory-only Malware loaders, to avoid detection.
  • Their methods enable two types of illegal revenue: mining cryptocurrency and selling access to compromised internet connections.
  • The attacks show a wider strategy, with attempts to spread to other systems and use multiple ways to remain hidden and profitable.

Security researchers reported that the group known as Mimo has started exploiting Magento CMS and misconfigured Docker systems in 2025. Previously, this group targeted vulnerable instances of Craft CMS. The group’s main motive is financial gain through cryptojacking and proxyware deployment, according to a recent report by Datadog Security Labs.

- Advertisement -

Researchers found that Mimo exploits certain security flaws in Magento, especially weaknesses in the PHP-FPM system used by the content management platform. After gaining access, the attackers use a tool called GSocket to control the server through a reverse shell. By disguising GSocket as a normal system process, they aim to avoid detection by security tools.

The group also uses an in-memory method to load another tool, 4l4md4r, without leaving files on disk. This loader deploys both the XMRig cryptocurrency miner and IPRoyal proxyware on infected systems. Before doing so, the attackers modify a sensitive system configuration file to help hide their presence. The proxyware lets criminals profit by quietly selling victims’ unused internet bandwidth to outside buyers, while the XMRig miner takes over the computer’s processing power to generate cryptocurrency.

According to Datadog, “This multi-layered monetization also enhances resilience: even if the crypto miner is detected and removed, the proxy component may remain unnoticed, ensuring continued revenue for the threat actor.” Mimo also attacks misconfigured Docker installations exposed to the internet. By running new containers, the group loads additional malware that can spread to other machines through SSH brute-force attacks. The malware, written in Go, can persist on systems, perform file operations, and shut down competing processes.

The recent string of attacks highlights Mimo’s ability to adapt quickly and use multiple attack methods, not just on content management systems but also widely used cloud and server technologies. Security experts believe this signals a broader trend where cybercriminals seek to maximize profits by using combined attack strategies on various digital platforms.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

AI Attack Wave: The Collapsing Exploit Window

The speed of AI-powered attacks is creating a Collapsing Exploit Window, drastically reducing the...

Tom Lee Predicts Ethereum Could Surge to $250,000

Fundstrat's Tom Lee expressed support for a Ethereum price target of $250,000 per coin,...

Blockchain Capital Raises $700M for Two New Funds

Blockchain Capital is raising $700 million across two new venture funds, its seventh early-stage...

Tesla Ramps $25B Capex for AI, FSD Milestone Ahead

Tesla plans capital expenditures exceeding $25 billion in 2026, focusing on autonomy, robotics, and...

Analyst: Bitcoin Price to Target $90K or Drop to $68K

Bitcoin's recent rally past $78,000 has revitalized market sentiment following a prolonged period of...

Must Read

How to Choose a Cryptocurrency Exchange: Major Risks and Expert Advice

During the bitcoin frenzy, in late 2017, Coinbase, one of the key players in the global cryptocurrency market, stopped trading operations. At a point...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading