news.mlab.sh
Back to the feed
malware

C0XMO botnet spreads via DD-WRT router flaw, kills rival malware

High
Summary

A new botnet, C0XMO, leveraging a DD-WRT router vulnerability (CVE-2021-27137) is spreading across various device architectures, including routers, DVRs, and Android devices. This botnet, developed by the Gafgyt group, is primarily used for DDoS attacks and exhibits a modular design allowing for rapid adaptation and expansion of its capabilities. The activity has been linked to a Japanese technology company, with the originating device located in Germany, highlighting the potential for global impact.

The C0XMO botnet is utilizing a buffer overflow vulnerability (CVE-2021-27137) within DD-WRT firmware to gain initial access to devices. Once established, the malware employs a sophisticated scanning strategy, targeting common ports and leveraging CPU architecture detection to deploy tailored binaries. The botnet’s modular design allows operators to dynamically update exploitation techniques and expand its reach across diverse platforms. Researchers at Fortinet identified C0XMO as having a significantly more advanced architecture than previous Gafgyt botnets, incorporating features like multi-stage command-and-control communication and a wide range of DDoS attack methods. The malware actively identifies and eliminates competing botnet clients and security tools to maintain operational integrity.

Read the full article at BleepingComputer