C0XMO Gafgyt Variant Exploits DD-WRT Routers via CVE-2021-27137

C0XMO Gafgyt Variant Exploits DD-WRT Routers via CVE-2021-27137

First seen 5 Jun 2026, 17:57 UTC GbhackersSocprimeCybersecuritynewsBleepingcomputerSecurityaffairs.Co 84% similarity 72.5

Article Content

Browse articles
ThreatCluster

A new Gafgyt botnet variant named C0XMO has emerged, targeting DD-WRT routers by exploiting CVE-2021-27137, a buffer overflow vulnerability in the UPnP service. This malware employs a Python-based scanner to propagate across various CPU architectures, utilizing weak credentials and DDoS capabilities. Once infected, it establishes persistence through hidden files, cron jobs, and shell profile modifications. The botnet communicates with its command-and-control server at 85.215.131.70. Organizations are advised to upgrade their DD-WRT firmware and disable unnecessary remote services. Indicators of compromise (IOCs) and defensive measures are provided for affected systems. The malware's ability to spread across different Linux devices highlights a significant shift in IoT malware tactics.

Key Points: • C0XMO exploits CVE-2021-27137 in DD-WRT routers to spread. • The malware uses a Python scanner for multi-architecture propagation. • Organizations should upgrade firmware and disable UPnP, Telnet, and SSH.

ThreatCluster AI

Timeline

2021-09-01
CVE-2021-27137 published
A buffer overflow vulnerability in the UPnP service of DD-WRT firmware was disclosed.
Socprime
2026-06-05
C0XMO Gafgyt variant identified
FortiGuard Labs reported the emergence of the C0XMO variant exploiting CVE-2021-27137.
Socprime
2026-06-05
Propagation methods detailed
C0XMO uses a Python scanner and weak credential attacks to spread across Linux devices.
Gbhackers

Community

Browse all →