News Ababil.
Explore
SYS_NODE: ONLINE // Cyber Security

C0XMO botnet hijacks DD‑WRT routers, outpaces Gafgyt in the wild

DECRYPTED BY: Kaelen Frost | TIMESTAMP: 2026-06-08 T 08:56:36 Z | [ 1 MIN READ ]
C0XMO botnet hijacks DD‑WRT routers, outpaces Gafgyt in the wild
1 Min Read
Share

C0XMO botnet exploits DD-WRT flaw

The C0XMO botnet, a fresh offshoot of the notorious Gafgyt family, is weaponising a long‑standing vulnerability in DD‑WRT router firmware to commandeer home gateways and expand across heterogeneous CPU architectures.

Researchers observed that the malware first compromises the router’s web interface, then injects a lightweight loader capable of downloading additional payloads for ARM, MIPS and x86 devices. Within weeks, infection counts surged, prompting a ↓ 45% dip in the rival Gafgyt’s active bots as C0XMO outcompetes it for resources.

“The speed at which C0XMO propagates suggests a sophisticated supply chain, possibly leveraging compromised firmware updates,” said a senior analyst at Reuters.

Security firms warn that the botnet’s modular design enables it to drop ransomware, cryptominers or espionage tools, turning ordinary routers into footholds for broader campaigns. Mitigation requires immediate firmware patches and disabling remote management ports.

For detailed remediation steps, see the advisory from Bloomberg Security.

Dispatch from: Kaelen Frost
Lead Cybersecurity Analyst
Global Data Feed

More from this Intel

Everest Forms Pro vulnerability fuels wave of WordPress takeovers

Everest Forms Pro vulnerability fuels wave of WordPress takeovers

Jun 07, 2026
Netherlands seizes servers in massive crackdown on Russian‑linked cyberhost

Netherlands seizes servers in massive crackdown on Russian‑linked cyberhost

Jun 07, 2026
AI Worms Poised to Become Enterprise’s Next Cyber Menace

AI Worms Poised to Become Enterprise’s Next Cyber Menace

Jun 05, 2026
Cisco Unified CM flaw patched after PoC exploit code surfaces

Cisco Unified CM flaw patched after PoC exploit code surfaces

Jun 04, 2026
Google Gemini Prompt Injection Exploit Lets Attackers Deploy Malicious Notifications

Google Gemini Prompt Injection Exploit Lets Attackers Deploy Malicious Notifications

Jun 03, 2026
Meta AI Support Bot Exploit Lets Hackers Hijack High‑Profile Instagram Accounts

Meta AI Support Bot Exploit Lets Hackers Hijack High‑Profile Instagram...

Jun 02, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.