logo

C0XMO botnet spreads via DD-WRT router flaw, kills rival malware

ID: 4c1d875a-d3e8-5902-b10c-97d06d366fdb

STIX ID: report--4c1d875a-d3e8-5902-b10c-97d06d366fdb

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-06-07

Date Updated: 2026-06-07

Author: Bill Toulas

...
...

Fortinet researchers discovered C0XMO, a modular Gafgyt variant that exploits CVE-2021-27137 and brute-forces credentials to infect a wide range of architectures and devices (ARM, MIPS, x86, PowerPC, SuperH, etc.), deploy persistent hidden binaries, remove competing malware, and provide 19 DDoS attack methods via a hardcoded C2 — indicating a sophisticated, actively distributed IoT botnet campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.