s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.c0xmo

📛 Threat Title

Malware family: C0XMO

Category: C0XMO First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.c0xmo`. Printable name: C0XMO.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:cyberpress.org

    A new variant of the Gafgyt botnet, tracked as C0XMO , is rapidly expanding its reach across multiple Linux architectures. Discovered earlier this year, this malware initially breaches systems by exploiting CVE-2021-27137, a stack buffer overflow vulnerability found in the UPnP service of specific DD-WRT routers.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to FortiGuard Labs, C0XMO is a newly identified Gafgyt variant that propagates by exploiting CVE-2021-27137 in DD-WRT routers, enabling remote attackers to control vulnerable systems. Unlike traditional Gafgyt, C0XMO modularizes its lateral movement into a standalone Python script, allowing it to efficiently target multiple Linux architectures. The malware is written in both Python ...

  • web:netcrook.com

    The malware variant tracked as C0XMO is tied to the Gafgyt family and is being described as active across multiple Linux architectures, with initial access reportedly gained through CVE-2021-27137 in the UPnP service of certain DD-WRT routers. The wire-level trigger is not exotic: specially crafted M-SEARCH requests sent over UDP port 1900.

  • web:socprime.com

    Summary FortiGuard Labs identified a new Gafgyt botnet strain named C0XMO that propagates by exploiting a buffer overflow flaw in DD-WRT routers tracked as CVE-2021-27137. The malware uses a separate Python-based scanner to broaden infections across different CPU architectures, while also relying on weak-credential attacks, several DDoS capabilities, and routines to remove competing malware ...

  • web:www.bleepingcomputer.com

    A new variant of the Gafgyt botnet called C0XMO is targeting DD-WRT router firmware and can move to other device types with various CPU architectures.

  • web:www.cyberthreatalliance.org

    Inside the Cross-Platform Propagation Strategy of a New Gafgyt Variant C0XMO

  • web:www.fortiguard.com

    Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO FortiGuard Labs analyzes C0XMO , a new Gafgyt variant leveraging DD-WRT exploitation and multi-architecture propagation to expand IoT botnet...

  • web:www.fortinet.com

    FortiGuard Labs analyzes C0XMO , a new Gafgyt variant leveraging DD-WRT exploitation and multi-architecture propagation to expand IoT botnet infections.

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

  • web:www.tenable.com

    Dirty Frag (CVE-2026-43284, CVE-2026-43500) is a Linux kernel local privilege escalation exploit chain with a public PoC affecting major Linux distributions.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.