Also known as: Mimo
Hezb is a group deploying cryptominers when new exploit are available for public facing vulnerabilities. The name is after the miner process they deploy.
Executive Summary
Hezb, also known as Mimo, is a criminal threat actor that deploys cryptominers when new exploits become available for public-facing vulnerabilities. The group's primary motivation is financial gain through unauthorized cryptocurrency mining. Hezb's activities pose a significant risk to organizations with unpatched vulnerabilities.
Goals & Targeting
Hezb's strategic objectives are centered around financial gain through cryptomining. The group targets sectors with vulnerable public-facing infrastructure, seeking to exploit newly discovered vulnerabilities to establish a foothold. Typical victims include organizations with unpatched systems, which are then commandeered for cryptocurrency mining. Hezb's targeting profile suggests a focus on ease of exploitation and potential revenue generation, rather than specific industry or geographic targeting.
Enhanced Description
Hezb is a threat actor that has been observed deploying cryptominers on compromised systems, leveraging newly discovered exploits for public-facing vulnerabilities. The name 'Hezb' is derived from the miner process they utilize. This group's primary objective is to harness computational resources for cryptocurrency mining, generating revenue through unauthorized means. Hezb's tactics, techniques, and procedures (TTPs) are characterized by the opportunistic exploitation of vulnerabilities, often targeting sectors with vulnerable public-facing infrastructure.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Hezb's campaign patterns are characterized by a rapid response to newly discovered vulnerabilities, often utilizing publicly available exploit code to compromise target systems. The group's operational tempo is marked by a focus on exploiting vulnerabilities before patches are widely applied, indicating a focus on ease of exploitation. Notable past operations have involved the exploitation of high-profile vulnerabilities, such as those in common software frameworks or libraries.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data is moderate, with some information gaps existing regarding Hezb's organizational structure and long-term objectives. Additional research and analysis are needed to fully understand the group's motivations and capabilities.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
15
IOCs
0
Observed Data
0
Tactics