C0XMO is a new Mirai-like botnet. Its scanner is implemented in Python for portability on various platforms. To infect new devices, apart from weak passwords in Telnet/SSH, it also tries several HTTP exploits.

https://www.fortinet.com/blog/threat-research/inside-cross-platform-propagation-of-new-gafgyt-variant-c0xmo

#C0xmo #malware #ddos #router #ddwrt

Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO | FortiGuard Labs

FortiGuard Labs analyzes C0XMO, a new Gafgyt variant leveraging DD-WRT exploitation and multi-architecture propagation to expand IoT botnet infections.…

Fortinet Blog

Fortinet researchers have uncovered C0XMO, an advanced Gafgyt variant that exploits a DD-WRT router flaw (CVE-2021-27137) for complete device takeover. This botnet doesn't just hijack bandwidth; it aggressively eliminates rival malware and establishes persistent control to launch sophisticated DDoS attacks. Discover the TTPs and crucial defenses against this evolving IoT threat.

https://www.tpp.blog/2bmuwu1

#cybersecurity #c0xmo #ddwrt

πŸ€– This post was AI-generated.

C0XMO botnet spreads via DD-WRT router flaw, kills rival malware

A new variant of the Gafgyt botnet called C0XMO is targeting DD-WRT router firmware and can move to other device types with various CPU architectures.

BleepingComputer
C0XMO botnet spreads via DD-WRT router flaw, kills rival malware

A new variant of the Gafgyt botnet called C0XMO is targeting DD-WRT router firmware and can move to other device types with various CPU architectures.

BleepingComputer

C0XMO Botnet Exploits DD-WRT Flaw to Spread, Disrupts Rival Malware

Meet C0XMO, a highly sophisticated botnet malware that's disrupting the status quo with its advanced architecture and modular design, allowing it to spread rapidly by exploiting flaws like the DD-WRT vulnerability CVE-2021-27137. Its operators can easily update and adapt the malware to launch devastating DDoS attacks.

https://osintsights.com/c0xmo-botnet-exploits-dd-wrt-flaw-to-spread-disrupts-rival-malware?utm_source=mastodon&utm_medium=social

#IotBotnet #C0xmoBotnet #Gafgyt #Ddwrt #Cve202127137

C0XMO Botnet Exploits DD-WRT Flaw to Spread, Disrupts Rival Malware

Discover how C0XMO botnet exploits DD-WRT flaw to spread and disrupt rival malware with advanced modular architecture, learn more about its sophisticated design now.

OSINTSights

Anyone running a #GLInet router? I've been running #ddwrt on a netgear for a long time. I thought about switching to #openwrt, gave it a try, and it went poorly.

Now we have gigabit fiber AND router buys are going to get dicey in the US in the future. I'm considering getting a #Flint3 even though we're OK now because it may be impossible to get here in a year.

Anyone have thoughts about the line and / or experience with them?

@nickbearded what is the cheapest alibaba arm device it will run on Netcore N60 Pro MediaTek MT7986A (Quad-core A53)? about 40 bucks, i have a few mango glinet and they are decent. you could also mkt this as a 4g/5g iot testbench. i see this as a way to sell product buy from alibaba in bulk, sell for double. it is a discrete product but also a gateway product #custom fw flashing #ddwrt #openwrt #routing protocols #debian arm
With the news of the US banning all foreign routers (well, all routers for practical purposes), I'm checking how to replace the one from my ISP (which, since I live in CR, is a #Huawei of all brands!). Now I'm down a rabbit hole of #GPON devices, #LC to #SFP adapters, and #DDWRT compatibility lists.
With the news of the US banning all foreign routers (well, all routers for practical purposes), I'm checking how to replace the one from my ISP (which, since I live in CR, is a #Huawei of all brands!). Now I'm down a rabbit hole of #GPON devices, #LC to #SFP adapters, and #DDWRT compatibility lists.
I had some strong firewall rules on my #ddwrt router blocking icmp requests from wan, blocking port scanners, and tarpitting, and absolutely murdered my throughout. I guess this poor mr8300 can't keep up. XD