Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO

June 4, 2026, 9:39 a.m.

Description

A new Gafgyt botnet variant named C0XMO has been discovered that spreads by exploiting a stack buffer overflow vulnerability in DD-WRT router firmware. Unlike earlier versions, this malware separates its lateral movement capabilities into a standalone Python script, enabling more efficient targeting of various system architectures including ARM, MIPS, PowerPC, and x86. The malware establishes persistence through cron jobs and shell profile modifications, eliminates competing botnets, and supports 19 different DDoS attack methods. Its scanner component performs weak-credential brute-force attacks on Telnet and SSH services while also exploiting multiple HTTP-based vulnerabilities and Android Debug Bridge unauthorized access. The malware connects to command-and-control infrastructure and demonstrates significantly more sophisticated architecture compared to traditional IoT botnets.

Date

  • Created: June 3, 2026, 10:14 p.m.
  • Published: June 3, 2026, 10:14 p.m.
  • Modified: June 4, 2026, 9:39 a.m.

Indicators

  • 444a9d34a9f59dc7975dfabefb47d789813a4497bbac9127c4806dd816e85211
  • 8fc2d35b66c692d37a85ae9d30dc5c7f06f0b3eaf01112a5a6398a1a0feb3aee
  • dff0edae6e8854ddd3e617054ee0bd74c696c91411f704dff60aabaec839bec9
  • d452f22dacab9785539484245c13e9cce58df23fc82eeef205684fcd196da20b
  • ea44138b9701fce1b2fe13de8f9e00681c007c9adc625edc9f507f177704c2e8
  • b61a5508847a2167b737d31193dc393e92c5be2aa5141bbe4b7ea6f440fd4799
  • eead44c0af7ddb12cece1a6125cf213bab3c22511cd59aff9d63dcfddb7d4386
  • 9394666007fac4014a4641fdae150c1b969ed2bc4299876318a336fd386abf59
  • 450ea44da0c9d96a2e8f4d6bad34f1c35cd35743295b8cd2defa9f7a9884685d
  • f02b1d8010dac35b007796def0cbd5d0c9414df790e2b55b105c95df2f2ffa91
  • 41e8e327abbf2ba721be677ad8a416a7295708257b39688a0af03275fb199cec
  • b6f835ced11059d341222eba11fff3a4672f4de47a3a4d791fad86059a2b06d4
  • 7413cbb6eab4d6b10346f71be5dd76d7cf2f4817f7776367b162f83755aefa1f
  • 3ddb67ab079509dd1e7ac77fc4cfed25a271526668c68f8a2221e96a4cc21812
  • 20042f1efb59c99e3addf822a3e9e5a496f0b701362df038a50a32a9f504a136
  • 217.160.125.125
  • 85.215.131.70
  • 176.100.37.91

Additional Informations

  • Technology
  • Japan

Linked vulnerabilities