Mimo, a financially motivated threat actor, exploited a critical remote code execution vulnerability (CVE-2025-32432) in Craft CMS shortly after its disclosure in April 2025. The group used the flaw to deploy web shells, execute malicious scripts, and install payloads like XMRig (a crypto miner) and residential proxyware for monetization. They also chained this with another Yii framework vulnerability (CVE-2024-58136) to escalate privileges and maintain persistence. Organizations using Craft CMS are strongly urged to act quickly and apply patches immediately.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox