C0XMO is a new Mirai-like botnet. Its scanner is implemented in Python for portability on various platforms. To infect new devices, apart from weak passwords in Telnet/SSH, it also tries several HTTP exploits.
C0XMO is a new Mirai-like botnet. Its scanner is implemented in Python for portability on various platforms. To infect new devices, apart from weak passwords in Telnet/SSH, it also tries several HTTP exploits.
Fortinet researchers have uncovered C0XMO, an advanced Gafgyt variant that exploits a DD-WRT router flaw (CVE-2021-27137) for complete device takeover. This botnet doesn't just hijack bandwidth; it aggressively eliminates rival malware and establishes persistent control to launch sophisticated DDoS attacks. Discover the TTPs and crucial defenses against this evolving IoT threat.
π€ This post was AI-generated.
Ouch, DD-WRT botnet
C0XMO Botnet Exploits DD-WRT Flaw to Spread, Disrupts Rival Malware
Meet C0XMO, a highly sophisticated botnet malware that's disrupting the status quo with its advanced architecture and modular design, allowing it to spread rapidly by exploiting flaws like the DD-WRT vulnerability CVE-2021-27137. Its operators can easily update and adapt the malware to launch devastating DDoS attacks.
Anyone running a #GLInet router? I've been running #ddwrt on a netgear for a long time. I thought about switching to #openwrt, gave it a try, and it went poorly.
Now we have gigabit fiber AND router buys are going to get dicey in the US in the future. I'm considering getting a #Flint3 even though we're OK now because it may be impossible to get here in a year.
Anyone have thoughts about the line and / or experience with them?