← BACK TO FEED
TAG

ddos1 articles

C0XMO Botnet Exploits DD-WRT Routers, Evicts Rival Malware to Claim Territory

C0XMO is a new, advanced variant of the Gafgyt botnet that exploits CVE-2021-27137, a buffer overflow vulnerability in DD-WRT router firmware, to spread across multiple device types and CPU architectures. It supports 19 DDoS attack methods, uses a Python-based scanner to brute-force credentials and move laterally across networks, and actively eliminates rival malware and security tools to maintain dominance on infected devices. Researchers at Fortinet describe it as significantly more sophisticated than typical IoT botnets, recommending that users keep devices patched, use strong credentials, and disable unnecessary remote access.

9 Jun 2026