Socprime
C0XMO Gafgyt Variant Exploits DD-WRT Routers via CVE-2021-27137
Article Content
A new Gafgyt botnet variant named C0XMO has emerged, targeting DD-WRT routers by exploiting CVE-2021-27137, a buffer overflow vulnerability in the UPnP service. This malware employs a Python-based scanner to propagate across various CPU architectures, utilizing weak credentials and DDoS capabilities. Once infected, it establishes persistence through hidden files, cron jobs, and shell profile modifications. The botnet communicates with its command-and-control server at 85.215.131.70. Organizations are advised to upgrade their DD-WRT firmware and disable unnecessary remote services. Indicators of compromise (IOCs) and defensive measures are provided for affected systems. The malware's ability to spread across different Linux devices highlights a significant shift in IoT malware tactics.
Key Points: • C0XMO exploits CVE-2021-27137 in DD-WRT routers to spread. • The malware uses a Python scanner for multi-architecture propagation. • Organizations should upgrade firmware and disable UPnP, Telnet, and SSH.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.