C0XMO is a modular Linux-focused variant of the Gafgyt IoT botnet, identified in March 2026. It targets internet-exposed routers, IoT devices, DVRs, and other embedded systems, initially exploiting CVE-2021-27137 in vulnerable DD-WRT UPnP implementations. Its propagation framework also performs random internet scanning, weak-credential attacks against Telnet and SSH, HTTP-based exploitation of multiple device and software vulnerabilities, and abuse of exposed Android Debug Bridge services. It identifies victim CPU architectures and deploys matching payloads across ARM, MIPS, PowerPC, SuperH, x86, and x64 systems; Android devices are also targeted through exposed ADB services. C0XMO separates scanning and lateral movement into a standalone Python component, permitting propagation methods to be updated independently of the core bot. The malware persists through concealed copies, scheduled-task execution, shell startup modifications, and process self-reexecution. It terminates competing botnets, security or administrative tooling, and associated persistence artifacts to monopolize compromised-device resources. Infected devices register with command-and-control infrastructure, can be directed to scan for further victims, and support 19 distributed-denial-of-service methods, including UDP, TCP, SYN, ICMP, HTTP flood, and amplification attacks. Activity was observed against a technology organization in Japan.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Attackers exploit CVE-2021-27137 in vulnerable DD-WRT routers by sending specially crafted SSDP M-SEARCH requests to UDP port 1900. Successful exploitation results in remote code execution and malware deployment. | A newly identified Gafgyt botnet variant, C0XMO, is actively targeting internet-exposed devices through vulnerability exploitation, weak-credential attacks, and automated lateral movement.
The scanner also includes numerous HTTP-based exploits for initial access, including... HNAP SOAP Injection (CVE-2015-2051). | FortiGuard Labs discovered a new Gafgyt botnet variant, C0XMO, that spreads by exploiting CVE-2021-27137. Our analysis revealed that, unlike earlier versions, this malware separates its lateral movement into a standalone Python script.
The scanner also includes numerous HTTP-based exploits for initial access, including... AVTECH DVR Vulnerability (CVE-2025-34054, CVE-2016-15047). | FortiGuard Labs discovered a new Gafgyt botnet variant, C0XMO, that spreads by exploiting CVE-2021-27137. Our analysis revealed that, unlike earlier versions, this malware separates its lateral movement into a standalone Python script.
The scanner also includes numerous HTTP-based exploits for initial access, including... GLPI htmLawed RCE (CVE-2022-35914). | FortiGuard Labs discovered a new Gafgyt botnet variant, C0XMO, that spreads by exploiting CVE-2021-27137. Our analysis revealed that, unlike earlier versions, this malware separates its lateral movement into a standalone Python script.
The scanner also includes numerous HTTP-based exploits for initial access, including... AVTECH DVR Vulnerability (CVE-2025-34054, CVE-2016-15047). | FortiGuard Labs discovered a new Gafgyt botnet variant, C0XMO, that spreads by exploiting CVE-2021-27137. Our analysis revealed that, unlike earlier versions, this malware separates its lateral movement into a standalone Python script.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
C0XMO copies itself to hidden paths at /tmp/.sys, /var/tmp/.sys, and /dev/shm/.sys...
It does so by deleting binaries and removing their persistence mechanisms, including cron jobs, init scripts, system services, and shell profile entries.
The scanner then begins large-scale internet scanning operations... Random Internet Scanning Initiated → Telnet, SSH, HTTP and ADB Exploitation Attempts Executed.
The malware scans active processes and terminates known botnets, security tools, administrative utilities, and competing malware families.
Target Architecture Identified → Matching Binary Deployed.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An IoT botnet described as a new Gafgyt variant that spreads via the DD-WRT router flaw CVE-2021-27137 and includes competitor-killing capability.
A botnet malware strain described in the references as a new Gafgyt variant that spreads via the DD-WRT router flaw and includes competitor-killing capability.
A Gafgyt variant that compromises internet-exposed devices, initially exploiting vulnerable DD-WRT routers via CVE-2021-27137. It deploys architecture-specific payloads, establishes persistence through hidden files, cron jobs, and shell startup modifications; removes competing malware; registers with C2; and downloads a separate Python scanner to scan and exploit Telnet, SSH, HTTP, and ADB-exposed targets. Infected systems become botnet nodes with DDoS capability.
A new Gafgyt-derived IoT botnet variant that exploits vulnerable routers and other internet-connected devices, installs persistence, kills competing malware and tools, uses a separate Python-based scanner for propagation, and supports large-scale DDoS attacks including UDP, TCP, SYN, ICMP, NTP, and Memcached amplification.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.