Hezb
Hezb is a group deploying cryptominers when new exploit are available for public facing vulnerabilities. The name is after the miner process they deploy.
Hezb (Mimo) deploys cryptominers on internet-exposed servers using newly available public-facing exploits.
Hezb (also known as Mimo) is a group deploying cryptominers once new exploits become available for public-facing vulnerabilities. They appear to target organizations with internet-exposed servers. Their main TTPs involve the exploitation of newly disclosed public-facing vulnerabilities and the deployment of a miner process named 'Hezb'. Defenders should focus on diligent patch management of internet-facing assets and monitor for unusual CPU spikes.
Hezb is a group deploying cryptominers when new exploit are available for public facing vulnerabilities. The name is after the miner process they deploy.
The Hezb group deploys cryptominers by exploiting newly disclosed public-facing vulnerabilities when new exploits become available.
The miner process deployed by Hezb is named 'Hezb'.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.