C0XMO Botnet Targets DD WRT Routers
A Gafgyt variant called C0XMO, discovered by FortiGuard Labs in March 2026, spreads by exploiting CVE-2021-27137, a five-year-old stack buffer overflow in the UPnP service of DD-WRT firmware. Its primary payload is DDoS attacks, supporting 19 attack methods.
It infects devices across multiple CPU architectures and then kills competing malware on the same system to claim resources.
The approach reuses familiar botnet tactics but adds a direct anti-rival step that reduces competition for bandwidth and compute.
The variant adapts quickly across device types after initial router compromise.
