logo

Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO

ID: 35fd3aaa-4af9-5bdc-a636-576c79273ce3

STIX ID: report--35fd3aaa-4af9-5bdc-a636-576c79273ce3

Feed Name: Fortinet Blog

Threat Score
78/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

...
...

**Executive summary:** FortiGuard Labs documents a sophisticated Gafgyt variant named C0XMO that actively exploits CVE-2021-27137 in DD-WRT UPnP to deliver multi-architecture binaries and a separate Python scanner for lateral movement; the malware implements multi-stage persistence, competitor-killing, a custom C2 handshake, and supports numerous DDoS modes, while the report includes C2/IP/file IOCs and mitigation guidance (patch firmware, disable UPnP/Telnet, enforce strong credentials).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.