Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Gafgyt Variant C0XMO Targets Linux Systems

New Gafgyt Variant C0XMO Targets Linux Systems

Posted on June 5, 2026 By CWS

A recent variation of the notorious Gafgyt botnet, dubbed C0XMO, has emerged, targeting Linux-based systems by exploiting a known vulnerability within DD-WRT router firmware. The malware capitalizes on a stack buffer overflow flaw found in the UPnP service of these routers, allowing attackers to gain unauthorized access without the need for credentials. Once a device is compromised, it becomes part of a rapidly expanding botnet.

Modular Design and Broader Reach

The C0XMO variant distinguishes itself through its modular architecture, enabling it to target a variety of Linux processor types simultaneously. Attackers have engineered the malware to deliver payloads tailored to specific architectures, significantly broadening its reach compared to previous IoT threats. Additionally, the malware employs Python scripts for network scanning and lateral movement, automatically identifying new targets within a network.

Researchers at Fortinet’s FortiGuard Labs were the first to identify and analyze this variant. Their findings, shared with Cyber Security News, indicate that C0XMO has been actively exploiting CVE-2021-27137 since March. This vulnerability is triggered by an oversized ST:uuid value in a crafted M-SEARCH request over UDP port 1900.

Impact and Cross-Platform Threats

The scope of C0XMO’s impact is under assessment, but the threat is notable given the widespread use of DD-WRT firmware in home and small business environments globally. Beyond targeting routers, the malware also seeks to exploit Android Debug Bridge connections, indicating a sophisticated cross-platform approach by IoT botnet operators.

In addition to its primary attack vector, C0XMO can execute distributed denial-of-service attacks once a device is enlisted. It also exploits vulnerabilities in D-Link devices, GLPI project software, and Avtech DVR cameras, significantly expanding its attack surface. Security teams overseeing diverse device environments should treat this as an ongoing threat.

Defensive Measures and Recommendations

C0XMO thrives on exploiting known vulnerabilities that often remain unpatched. It utilizes CVE-2021-27137 in DD-WRT, CVE-2015-2051 in D-Link devices, CVE-2022-35914 in GLPI software, and various Avtech DVR camera flaws. To mitigate risk, users should promptly update firmware and disable unnecessary UPnP services on their routers. Blocking external access to UDP port 1900 can further reduce exposure.

Monitoring network traffic for unusual activity, such as unexpected UDP traffic spikes or brute-force login attempts, is crucial for early detection of infections. Special attention should be given to older, unmanaged IoT devices, which are often left unpatched and are prime targets for such malware campaigns.

Indicators of Compromise (IoCs) include specific CVEs and IP addresses associated with the C0XMO botnet. Security professionals are advised to refang IP addresses within controlled environments to avoid accidental resolutions.

Cyber Security News Tags:Botnet, C0XMO, cross-platform malware, Cybersecurity, DD-WRT, DDoS, Fortinet, Gafgyt, IoT, Linux, Malware, network security, Python scripts, router exploitation, Vulnerabilities

Post navigation

Previous Post: Hackers Exploit System Tools to Deploy Malware
Next Post: Anthropic’s Claude Services Experience Major Disruption

Related Posts

Banana RAT Targets Brazilian Financial Sector with NF-e Lures Banana RAT Targets Brazilian Financial Sector with NF-e Lures Cyber Security News
Iranian Nation-State APT Targeting Networks and Critical Infrastructure Organizations Iranian Nation-State APT Targeting Networks and Critical Infrastructure Organizations Cyber Security News
Active Exploitation of Windows Defender Zero-Day Flaws Active Exploitation of Windows Defender Zero-Day Flaws Cyber Security News
New SAP NetWeaver Vulnerabilities Allow Attackers to Bypass Authorization and Execute OS Commands New SAP NetWeaver Vulnerabilities Allow Attackers to Bypass Authorization and Execute OS Commands Cyber Security News
SCADA Vulnerability Triggers DoS, Potentially Disrupting Industrial Operations SCADA Vulnerability Triggers DoS, Potentially Disrupting Industrial Operations Cyber Security News
Swarmer Tool Evading EDR With a Stealthy Modification on Windows Registry for Persistence Swarmer Tool Evading EDR With a Stealthy Modification on Windows Registry for Persistence Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes
  • Cisco Introduces Cost-Effective AI for Code Security
  • Accelerating Exploit Timelines Challenge Defenders
  • Teach Claude Skills Easily with Screen Recording
  • Trump Initiates Defense Supply Chain Security Overhaul

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes
  • Cisco Introduces Cost-Effective AI for Code Security
  • Accelerating Exploit Timelines Challenge Defenders
  • Teach Claude Skills Easily with Screen Recording
  • Trump Initiates Defense Supply Chain Security Overhaul

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark