The images in this article were generated with artificial intelligence. How we publish
Fortinet researchers have exposed a new iteration of the old known Gafgyt, baptized as C0XMO, which shows how the botnet families for IoT continue to evolve towards more modular and resilient architectures. Unlike simplistic campaigns that only point to a type of CPU or a specific operation, C0XMO incorporates components that allow you to explore multiple vectors, add or remove architectural objectives and expand your lateral motion routines without necessarily touching the main binary.
One of the signs of this sophistication is the support for multiple architectures - ARM, MIPS, PowerPC, SuperH, x86, x86 _ 64 and others - and the ability to exploit devices as diverse as DVR recorders, routers with DD-WRT firmware, video management platforms and Android devices. This multi-purpose approach multiplies the attack surface and forces administrators and manufacturers to defend layers very different from the IoT ecosystem. You can read the technical analysis of Fortinet in your report: Fortinet Labs: C0XMO.

The delivery vector highlighted in the findings is the exploitation of vulnerability CVE-2021-27137, a buffer overflow that allows code execution without authentication under certain conditions. That fragility in components exposed to the public Internet facilitates the initial entry, after which malware download a Python installer that adds modules like requests, paramiko and beautifulsoup4 to scan networks, communicate through SSH / Telnet and move laterally. The details of the CVE are documented in the NVD database: CVE-2021-27137 (NVD).
The C0XMO scanner operates with working threads that explore common ports - 22, 23, 80, 443, 7547, 8080, 8443, 8888, among others - to detect exposed services, test weak credentials and deploy the binary compatible with the detected architecture. This combination of remote operation and brute force against Telnet / SSH is a classic recipe that remains effective because thousands of devices still use default credentials or trivial passwords.
Once compromised, malware continues to copy into time-hidden locations like / tmp / .sys, / var / tmp / .sys or / dev / shm / .sys, creating cron inputs to relaunch every 15 minutes and modifying shell start files. It also seeks and removes customers from competing botnets, network tools and pentesting suites, deleting binaries and their persistence mechanisms to monopolize the infected device.
In its main function, C0XMO is a DDoS attack launcher with support for 19 different methods: UDP / TCP / SYN / ICMP floods, ping of death, NTP amplification and Memcached, UDP voice attacks to Discord and specific variants for game services (Valve), among others. This flexibility allows operators to adapt the campaign to the objective and to use amplification techniques to maximize impact with few own resources.
The commitment indicators to be reviewed include unusual peaks of outgoing traffic (especially UDP), new or modified processes, foreign entries in chronab, files hidden on temporary routes and the disappearance of utilities or diagnostic tools. If you detect activity that matches these patterns, the device is likely to be under remote control and should be isolated immediately.

To reduce the risk of infection with C0XMO or other IoT botnets, practical measures range from basic to network architecture changes: keep up-to-date firmware, disable remote access when not required, replace default passwords with unique and robust credentials and disable Telnet in favour of SSH with key authentication. In addition, segmenting IoT devices in separate VLANs, applying output filtering (egress filtering) and blocking unnecessary ports and services on the perimeter limits scanning capacity and lateral mobility.
In business environments, it is appropriate to complement these actions with network-based detection (IDS / IPS), file integrity monitoring, DNS inspection and dynamic block lists for C2, and periodic penetration tests that simulate these vectors. The response guides should consider the physical disconnection of the device, the collection of logs before a factory restoration and the rotation of credentials. An accessible summary of the case and its media coverage can be found in the BleepingComputer article: BleepingComputer on C0XMO.
Finally, while technical mitigation is essential, real defence requires processes: continuous inventory of connected devices, mandatory updating policies, and training for network and operational teams to recognize early signals. The modularity and multi-architecture support of C0XMO are not a technical curiosity: they are a warning that modern botnets adapt quickly and that network security begins by closing the most obvious doors: patched firmware, controlled remote access and unique credentials.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...