FortiGuard Labs has analyzed C0XMO, a new Gafgyt botnet variant discovered in March that exploits CVE-2021-27137, a stack buffer overflow in the UPnP service of DD-WRT router firmware. Unlike earlier Gafgyt variants, C0XMO separates its lateral movement into a standalone Python scanner script, enabling it to target multiple CPU architectures (ARM, MIPS, PowerPC, x86_64, etc.). The malware establishes persistence via cron jobs and shell profile modifications, kills competing botnets, and connects to a C2 server using a custom handshake. It supports 19 DDoS attack methods and uses a modular scanner with Telnet/SSH brute-force, HTTP-based CVE exploits (including GLPI, AVTECH DVR, Zyxel, D-Link), and Android Debug Bridge (ADB) exploitation for propagation. Indicators of compromise and Fortinet detection signatures are provided.