FortiGuard Labs has analyzed C0XMO, a new Gafgyt botnet variant discovered in March that exploits CVE-2021-27137, a stack buffer overflow in the UPnP service of DD-WRT router firmware. Unlike earlier Gafgyt variants, C0XMO separates its lateral movement into a standalone Python scanner script, enabling it to target multiple CPU architectures (ARM, MIPS, PowerPC, x86_64, etc.). The malware establishes persistence via cron jobs and shell profile modifications, kills competing botnets, and connects to a C2 server using a custom handshake. It supports 19 DDoS attack methods and uses a modular scanner with Telnet/SSH brute-force, HTTP-based CVE exploits (including GLPI, AVTECH DVR, Zyxel, D-Link), and Android Debug Bridge (ADB) exploitation for propagation. Indicators of compromise and Fortinet detection signatures are provided.

10m read timeFrom feeds.fortinet.com
Post cover image
Table of contents
Malware AnalysisConclusionFortinet ProtectionsIOCs
194 Impressions