logo

IoT Botnet C0XMO Adds Competitor-Killing Capability

ID: 9c05c1b0-aa18-5f14-8742-db43873f47ff

STIX ID: report--9c05c1b0-aa18-5f14-8742-db43873f47ff

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-06-08

Date Updated: 2026-06-08

Author: Pierluigi Paganini

...
...

FortiGuard Labs identified C0XMO, a new variant of the Gafgyt IoT botnet that exploits an unpatched DD-WRT UPnP stack overflow (CVE-2021-27137) and multiple other device vulnerabilities to infect many architectures, persist via hidden copies and cron/profile modifications, remove competing malware, and enable large-scale DDoS operations using a modular design with a separate Python scanner and extensive attack modules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.