Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Gafgyt Variant C0XMO Targets Linux Systems

New Gafgyt Variant C0XMO Targets Linux Systems

Posted on June 5, 2026 By CWS

A recent variation of the notorious Gafgyt botnet, dubbed C0XMO, has emerged, targeting Linux-based systems by exploiting a known vulnerability within DD-WRT router firmware. The malware capitalizes on a stack buffer overflow flaw found in the UPnP service of these routers, allowing attackers to gain unauthorized access without the need for credentials. Once a device is compromised, it becomes part of a rapidly expanding botnet.

Modular Design and Broader Reach

The C0XMO variant distinguishes itself through its modular architecture, enabling it to target a variety of Linux processor types simultaneously. Attackers have engineered the malware to deliver payloads tailored to specific architectures, significantly broadening its reach compared to previous IoT threats. Additionally, the malware employs Python scripts for network scanning and lateral movement, automatically identifying new targets within a network.

Researchers at Fortinet’s FortiGuard Labs were the first to identify and analyze this variant. Their findings, shared with Cyber Security News, indicate that C0XMO has been actively exploiting CVE-2021-27137 since March. This vulnerability is triggered by an oversized ST:uuid value in a crafted M-SEARCH request over UDP port 1900.

Impact and Cross-Platform Threats

The scope of C0XMO’s impact is under assessment, but the threat is notable given the widespread use of DD-WRT firmware in home and small business environments globally. Beyond targeting routers, the malware also seeks to exploit Android Debug Bridge connections, indicating a sophisticated cross-platform approach by IoT botnet operators.

In addition to its primary attack vector, C0XMO can execute distributed denial-of-service attacks once a device is enlisted. It also exploits vulnerabilities in D-Link devices, GLPI project software, and Avtech DVR cameras, significantly expanding its attack surface. Security teams overseeing diverse device environments should treat this as an ongoing threat.

Defensive Measures and Recommendations

C0XMO thrives on exploiting known vulnerabilities that often remain unpatched. It utilizes CVE-2021-27137 in DD-WRT, CVE-2015-2051 in D-Link devices, CVE-2022-35914 in GLPI software, and various Avtech DVR camera flaws. To mitigate risk, users should promptly update firmware and disable unnecessary UPnP services on their routers. Blocking external access to UDP port 1900 can further reduce exposure.

Monitoring network traffic for unusual activity, such as unexpected UDP traffic spikes or brute-force login attempts, is crucial for early detection of infections. Special attention should be given to older, unmanaged IoT devices, which are often left unpatched and are prime targets for such malware campaigns.

Indicators of Compromise (IoCs) include specific CVEs and IP addresses associated with the C0XMO botnet. Security professionals are advised to refang IP addresses within controlled environments to avoid accidental resolutions.

Cyber Security News Tags:Botnet, C0XMO, cross-platform malware, Cybersecurity, DD-WRT, DDoS, Fortinet, Gafgyt, IoT, Linux, Malware, network security, Python scripts, router exploitation, Vulnerabilities

Post navigation

Previous Post: Hackers Exploit System Tools to Deploy Malware

Related Posts

BadIIS Malware Exploits IIS Servers for Illicit Redirects BadIIS Malware Exploits IIS Servers for Illicit Redirects Cyber Security News
Researchers Exploited Google kernelCTF Instances And Debian 12 With A 0-Day Researchers Exploited Google kernelCTF Instances And Debian 12 With A 0-Day Cyber Security News
CloudEyE MaaS Downloader and Cryptor Infects 100,000+ Users Worldwide CloudEyE MaaS Downloader and Cryptor Infects 100,000+ Users Worldwide Cyber Security News
PoC Exploit Unveiled for Lenovo Code Execution Vulnerability Enabling Privilege Escalation PoC Exploit Unveiled for Lenovo Code Execution Vulnerability Enabling Privilege Escalation Cyber Security News
Critical Flaw in Cisco Unified CM Exposes Systems to Exploits Critical Flaw in Cisco Unified CM Exposes Systems to Exploits Cyber Security News
GlassWorm Exploits VSX Extensions to Target Developers GlassWorm Exploits VSX Extensions to Target Developers Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Gafgyt Variant C0XMO Targets Linux Systems
  • Hackers Exploit System Tools to Deploy Malware
  • New Malware Strikes npm with IronWorm and Miasma Variants
  • OWASP Project Enhances Security by Identifying Vulnerable Dependencies
  • Android Spyware Asin Targets Arabic Users via Fake Apps

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Gafgyt Variant C0XMO Targets Linux Systems
  • Hackers Exploit System Tools to Deploy Malware
  • New Malware Strikes npm with IronWorm and Miasma Variants
  • OWASP Project Enhances Security by Identifying Vulnerable Dependencies
  • Android Spyware Asin Targets Arabic Users via Fake Apps

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark