C0XMO Gafgyt botnet activity on DD-WRT routers
Malware Activity
Updated: 07.06.2026 17:17
· First: 07.06.2026 17:17
· 📰 1 src / 1 articles
· H score: 19
The C0XMO botnet is spreading through DD-WRT router firmware and other internet-facing devices, increasing the pool of systems available for DDoS attacks. It exploits CVE-2021-27137 for unauthenticated code execution, then brute-forces SSH and Telnet credentials to expand. The malware can persist with cron jobs and shell startup changes, detect CPU architecture, deploy a matching binary, and remove rival botnet clients. Its support for 19 DDoS methods makes each infected device useful for both propagation and attack traffic.