Skip to content

New Gafgyt Variant Targets Linux Systems With Modular Spread Tactics

Gbhackers Mayura Kathir June 5, 2026

A new Gafgyt-family botnet, tracked as C0XMO, marks a notable technical shift in IoT malware design: the separation of scanning and propagation into distinct components and multi-architecture payloads that maximize reach across heterogeneous Linux devices. The operator delivered C0XMO by exploiting CVE-2021-27137 a stack buffer overflow in the UPnP SSDP parser of vulnerable DD-WRT firmware […]

Extracted Entities

Attack Types (1)

Malware (1)

Platforms (2)