<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware-h3aopvaei" -->

---
title: C0XMO botnet spreads via DD-WRT router flaw, kills rival...
description: A new Gafgyt botnet variant called C0XMO is actively exploiting CVE-2021-27137, a buffer overflow vulnerability in DD-WRT router firmware, to spread across...
canonical: https://daily.dev/posts/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware-h3aopvaei
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: C0XMO botnet spreads via DD-WRT router flaw, kills rival malware | daily.dev
og:description: A new Gafgyt botnet variant called C0XMO is actively exploiting CVE-2021-27137, a buffer overflow vulnerability in DD-WRT router firmware, to spread across...
og:url: https://daily.dev/posts/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware-h3aopvaei
og:image: https://api.daily.dev/og/posts/h3AopVAei.png
og:image:alt: C0XMO botnet spreads via DD-WRT router flaw, kills rival malware
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# C0XMO botnet spreads via DD-WRT router flaw, kills rival malware

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

A new Gafgyt botnet variant called C0XMO is actively exploiting CVE-2021-27137, a buffer overflow vulnerability in DD-WRT router firmware, to spread across multiple CPU architectures including ARM, MIPS, x86, and others. The botnet features a modular design, supports 19 DDoS attack methods (UDP/TCP/SYN floods, NTP/Memcached amplification, and more), and uses a Python-based scanner to brute-force SSH/Telnet credentials for lateral movement. Notably, C0XMO actively hunts and kills competing botnet clients and red-team tools on infected hosts, removes their persistence mechanisms, and establishes its own via cron jobs and shell startup modifications. Fortinet researchers describe it as significantly more sophisticated than typical Gafgyt variants. Mitigation advice includes keeping firmware updated, using strong unique credentials, and disabling unnecessary remote access.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware>

## Similar posts on daily.dev

- [Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO](https://daily.dev/posts/inside-the-cross-platform-propagation-of-a-new-gafgyt-variant-c0xmo-fgt1kdoi9) · FortiGuard Threat Research · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber)

[View this post on daily.dev](https://daily.dev/posts/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware-h3aopvaei)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"C0XMO botnet spreads via DD-WRT router flaw, kills rival malware","url":"https://daily.dev/posts/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware-h3aopvaei","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware-h3aopvaei"},"datePublished":"2026-06-07T14:20:53.332Z","dateModified":"2026-06-07T14:21:17.376Z","description":"A new Gafgyt botnet variant called C0XMO is actively exploiting CVE-2021-27137, a buffer overflow vulnerability in DD-WRT router firmware, to spread across...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4493e4731e39a9939bcc72796dace47f?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4493e4731e39a9939bcc72796dace47f?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware-h3aopvaei","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cyber","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"C0XMO botnet spreads via DD-WRT router flaw, kills rival malware"}]}
```

