Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Mimo

Description

Hezb is a group deploying cryptominers when new exploit are available for public facing vulnerabilities. The name is after the miner process they deploy.

AI Analysis

· 2 weeks ago

Executive Summary

Hezb, also known as Mimo, is a criminal threat actor that deploys cryptominers when new exploits become available for public-facing vulnerabilities. The group's primary motivation is financial gain through unauthorized cryptocurrency mining. Hezb's activities pose a significant risk to organizations with unpatched vulnerabilities.

Goals & Targeting

Hezb's strategic objectives are centered around financial gain through cryptomining. The group targets sectors with vulnerable public-facing infrastructure, seeking to exploit newly discovered vulnerabilities to establish a foothold. Typical victims include organizations with unpatched systems, which are then commandeered for cryptocurrency mining. Hezb's targeting profile suggests a focus on ease of exploitation and potential revenue generation, rather than specific industry or geographic targeting.

Enhanced Description

Hezb is a threat actor that has been observed deploying cryptominers on compromised systems, leveraging newly discovered exploits for public-facing vulnerabilities. The name 'Hezb' is derived from the miner process they utilize. This group's primary objective is to harness computational resources for cryptocurrency mining, generating revenue through unauthorized means. Hezb's tactics, techniques, and procedures (TTPs) are characterized by the opportunistic exploitation of vulnerabilities, often targeting sectors with vulnerable public-facing infrastructure.

Key Capabilities

  • Exploit development and utilization
  • Cryptomining and cryptocurrency manipulation
  • Vulnerability scanning and exploitation
  • System compromise and persistence

MITRE ATT&CK Tactics

Execution
Persistence
Privilege Escalation

ATT&CK Techniques

T1190
T1204
T1059.003
T1055

Software / Tooling

Custom cryptominer
Exploit kits

Campaigns & Victims

Hezb's campaign patterns are characterized by a rapid response to newly discovered vulnerabilities, often utilizing publicly available exploit code to compromise target systems. The group's operational tempo is marked by a focus on exploiting vulnerabilities before patches are widely applied, indicating a focus on ease of exploitation. Notable past operations have involved the exploitation of high-profile vulnerabilities, such as those in common software frameworks or libraries.

IOC Patterns

  • Spear-phishing with exploit-laced Office documents
  • C2 over HTTP/HTTPS using compromised websites
  • Staging infrastructure on compromised systems

Recommended Actions

  • Implement robust patch management and vulnerability remediation
  • Monitor for suspicious system activity and cryptomining behavior
  • Utilize threat intelligence to inform defensive strategies

Suggested Tags

Cryptomining
Exploit
Vulnerability
Criminal

Confidence Assessment

The confidence level in the available data is moderate, with some information gaps existing regarding Hezb's organizational structure and long-term objectives. Additional research and analysis are needed to fully understand the group's motivations and capabilities.

Intel Summary

0

Techniques

0

Tools

1

Campaigns

15

IOCs

0

Observed Data

0

Tactics

Details

Type
Criminal
Confidence
70%
Added
May 6, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.