Socprime
C0XMO Gafgyt Variant Exploits DD-WRT Routers via CVE-2021-27137
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A new Gafgyt botnet variant named C0XMO has emerged, targeting DD-WRT routers by exploiting CVE-2021-27137, a buffer overflow vulnerability in the UPnP service. This malware employs a Python-based scanner to propagate across various CPU architectures, utilizing weak credentials and DDoS capabilities. Once infected, it establishes persistence through hidden files, cron jobs, and shell profile modifications. The botnet communicates with its command-and-control server at 85.215.131.70. Organizations are advised to upgrade their DD-WRT firmware and disable unnecessary remote services. Indicators of compromise (IOCs) and defensive measures are provided for affected systems. The malware's ability to spread across different Linux devices highlights a significant shift in IoT malware tactics.
Key Points: • C0XMO exploits CVE-2021-27137 in DD-WRT routers to spread. • The malware uses a Python scanner for multi-architecture propagation. • Organizations should upgrade firmware and disable UPnP, Telnet, and SSH.