Mimo Exploits Craft CMS Flaw
- CVE-2025-32432 used for remote code execution.
- Deploys web shell, cryptominer, and proxyware.
- Uses “fbi” alias in Python for urllib2 import.
- Mimo Loader hides malware via
ld.so.preload. - Final payloads include XMRig and IPRoyal proxyware.
