logo

New Gafgyt Variant Targets Linux Systems With Modular Spread Tactics

ID: 1f762458-de4c-5491-a02a-2a755725ec84

STIX ID: report--1f762458-de4c-5491-a02a-2a755725ec84

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Mayura Kathir

...
...

**Executive summary:** A technical analysis of C0XMO, a Gafgyt-family IoT botnet that exploits CVE-2021-27137 to compromise DD-WRT and other devices, using a modular design that separates an extensible Python scanner from lightweight multi-architecture binaries; the report describes persistence, competitor-removal, a custom C2 protocol, 19 DDoS methods, IOCs (hosts and hashes), and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.