logo

COXMO Botnet Variant: New Advanced Threat Exploits Router Firmware

ID: a37ac271-cb9b-5c2a-be15-6f78fa1a65da

STIX ID: report--a37ac271-cb9b-5c2a-be15-6f78fa1a65da

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Do Son

...
...

Security researchers identified an active COXMO botnet variant targeting internet-connected infrastructure by exploiting known router firmware vulnerabilities (CVE-2021-27137). The malware deploys architecture-specific payloads, establishes persistence via hidden files and frequent cron jobs, removes competing botnets, and connects to command servers using cryptographic handshakes to receive instructions for large-scale DDoS (19 flood methods). Lateral propagation is handled by a separate Python scanning module that exploits routers, databases, and exposed ADB interfaces, highlighting a scalable, modular campaign that requires urgent patching and hardening of edge devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.