ZeroHour
Security Affairspublished ()ingested @securityaffairs

IoT Botnet C0XMO Adds Competitor

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2015-2051
Remote Command Execution via HNAP GetDeviceSettings in D-Link DIR-645 Router

The D-Link DIR-645 wired/wireless router is vulnerable to OS command injection (CWE-77) in its HNAP interface: input supplied to the GetDeviceSettings action is not properly neutralized, so a remote attacker who sends a crafted HTTP request to the router's HNAP endpoint can have arbitrary operating-system commands executed on the device. Successful exploitation gives the attacker control of the router at the system level, enabling reconfiguration or abuse of the device, traffic interception or redirection, and recruitment into IoT botnets, as reflected in recent Moobot/MooBot botnet campaigns. Any site or household still running a DIR-645, especially one whose web/HNAP management interface is reachable from the internet, is affected; the product is end-of-life. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-02-10, and EPSS assigns a 97.1% probability of exploitation within 30 days (100th percentile). CISA's required action reflects the risk: disconnect the impacted product if it is still in use because it has reached end-of-life.

Do: Because the DIR-645 is end-of-life, CISA's required action is to disconnect it; replace the device where possible, or at minimum apply the latest available D-Link firmware for the DIR-645 and ensure the management/HNAP interface is not reachable from the internet (block or restrict remote administration on the WAN side). Check the device for signs of botnet infection, such as unexpected outbound traffic or unexpected HNAP POST/SOAP requests, and prioritize this fix given the 97.1% EPSS score and known in-the-wild exploitation.

97% KEV
  • D-Link DIR-645 Wired/Wireless Router
largetens of thousands of internet-exposed devices (est.; far more DIR-645 units exist behind NAT given the product's broad consumer/SOHO distribution)
CVE-2016-15047
AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection.

AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection. The `exefile` parameter in CloudSetup.cgi is passed to the underlying system command execution without proper validation or whitelisting. An authenticated attacker who can invoke this endpoint can supply crafted input to execute arbitrary system commands as root. Successful exploitation grants full control of the device, and - depending on deployment and whether the device stores credentials or has network reachability to internal systems - may enable credential theft, lateral movement, or data exfiltration. The archived SEARCH-LAB disclosure implies that this vulnerability was remediated in early 2017, but AVTECH has not defined an affected version range.

NVD description · AI analysis pending
8.74%
CVE-2021-27137
Unauthenticated Stack-Based Buffer Overflow in DD-WRT UPnP (SSDP M-SEARCH)

DD-WRT firmware before build 45724 contains a stack-based buffer overflow (CWE-121) caused by an unsafe strcpy in the UPnP handling code (ssdp_msearch in router/upnp/src/ssdp.c). An unauthenticated remote attacker can trigger it by sending a crafted SSDP M-SEARCH request to a UPnP-enabled interface, overflowing an internal fixed buffer. Successful exploitation can crash the router or allow code execution and full device compromise, consistent with the high confidentiality, integrity and availability impacts in the 8.1 CVSS score. Exposure is limited because UPnP is disabled by default and, by default, listens only on internal interfaces, so risk is concentrated on DD-WRT routers where UPnP has been enabled and on networks where an attacker has LAN access. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-21, has public proofs of concept, and is reportedly being exploited in the wild by the C0XMO IoT botnet (a Gafgyt variant) to propagate and remove rival malware.

Do: Upgrade affected DD-WRT routers to build 45724 or later. If upgrading is not immediately possible, disable UPnP, or verify that UPnP/SSDP is bound only to internal interfaces and that UDP port 1900 (SSDP) and M-SEARCH traffic are not reachable from the WAN. Per the CISA KEV required action, apply mitigations in line with BOD 26-04 guidance, and check any internet-exposed DD-WRT device for signs of compromise (e.g., unexpected botnet traffic) if UPnP was enabled.

8.14% KEV PoC ×4
  • DD-WRT firmware All builds before 45724
large≈ hundreds of thousands of DD-WRT routers, of which only the subset with UPnP enabled is actually exploitable
CVE-2022-35914
Unauthenticated PHP Code Injection RCE in GLPI via bundled htmlawed (through 10.0.2)

GLPI, a widely deployed open-source IT asset management platform, bundles a third-party htmlawed library whose htmLawedTest.php script permits unauthenticated PHP code injection (CWE-74) in GLPI versions through 10.0.2. An attacker triggers it by sending a crafted HTTP request with injected PHP parameters to the directly web-reachable /vendor/htmlawed/htmlawed/htmLawedTest.php script, with no authentication and no user interaction required (AV:N/AC:L/PR:N/UI:N). Successful exploitation yields remote code execution on the web server as the web service account, enabling data theft, lateral movement, and follow-on activity such as ransomware staging or botnet recruitment. Any organization running GLPI 10.0.2 or earlier is affected, particularly internet-facing instances where the test script is directly reachable. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities Catalog on 2023-03-07 (required action: apply vendor updates), carries a 99.7% EPSS score, and multiple public proof-of-concept exploits are available.

Do: Upgrade GLPI to a fixed release newer than 10.0.2 (or update the bundled htmlawed library to a patched version); as an interim mitigation, remove or block direct web access to /vendor/htmlawed/htmlawed/htmLawedTest.php. Prioritize internet-facing instances given active exploitation and the 99.7% EPSS score, and review web access logs for requests to htmLawedTest.php plus signs of webshells or unexpected administrator accounts. As a CISA KEV entry, federal agencies and other KEV subscribers are required to apply vendor updates per the catalog instructions.

9.8100% KEV PoC ×3
  • glpi-project (Teclib') GLPI 10.0.2 and earlier
largeon the order of tens of thousands of internet-exposed GLPI instances (unknown for internal deployments)
CVE-2025-34054
An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi?action=cgi_query.

An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi?action=cgi_query. The use of wget without input sanitization allows attackers to inject shell commands through the username or queryb64str parameters, executing commands as root. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-04 UTC.

NVD description · AI analysis pending
10.03%

Indicators of compromiseAll →

TypeIndicatorContext
ipv4217.160.125.125work-attached device. The attacker’s distribution server at 217.160.125.125:15527 serves both the main bot binary and the Python scanne
Full article801 words · extracted from securityaffairs.com · click to collapse

C0XMO is a new Gafgyt botnet variant exploiting old router flaws, spreading across IoT devices, killing rivals, and enabling large-scale DDoS attacks.

In March 2026, FortiGuard Labs discovered a new variant of the Gafgyt botnet, dubbed C0XMO, which is noticeably more capable than its predecessors. The malware spreads through CVE-2021-27137, a stack buffer overflow in the UPnP service of DD-WRT router firmware that’s been sitting unpatched on countless devices since 2021. The entry point is a crafted UDP packet sent to port 1900, exploiting how the SSDP parser handles oversized values in M-SEARCH requests. The attack doesn’t require authentication.

The initial target was a Japanese technology company, but the source IP traced back to a device in Germany, which tells you something about how these networks operate. Once inside, C0XMO downloads binaries compiled for ARM, MIPS, PowerPC, SuperH, x86, and x86_64, covering essentially every Linux architecture you’d find in a router, DVR, or network-attached device. The attacker’s distribution server at 217.160.125.125:15527 serves both the main bot binary and the Python scanner script that drives lateral movement.

The persistence mechanism runs in four stages. C0XMO copies itself to hidden paths at /tmp/.sys, /var/tmp/.sys, and /dev/shm/.sys, sets permissions to 755, creates cron jobs that relaunch it every 15 minutes, and appends execution commands to shell profile files like .bashrc and .bash_profile. If the process gets killed for any reason, it relaunches itself automatically. The operators clearly wanted this to survive basic cleanup attempts.

After locking itself in, C0XMO goes after the neighborhood. It scans every active process in /proc against an internal blacklist and terminates anything that matches: competing botnets, red team tools, network services, programming utilities. Then it goes further.

“C0XMO attempts to eliminate competing botnets run by other threat actors.” states the report. “It not only deletes rival malware binaries but also tries to remove associated persistence mechanisms such as cron jobs, rc.local, init.d services, system services, and shell profile scripts.”

The malware uses a custom command-and-control (C2) system with a three-step handshake to connect to its server. First, the bot sends a secret string and waits for a reply. Then it identifies itself as a bot, receives confirmation, and sends a final code before entering standby mode. Once connected, it waits for instructions such as checking status, starting or stopping scans, or launching attacks. The attack options are extensive, with 19 different methods.

It can launch many types of DDoS attacks, including UDP, TCP, SYN and ICMP floods, as well as amplification attacks like NTP and Memcached. It also targets gaming services, voice platforms, and tries to bypass protections like OVH and Cloudflare. This shows the operators are not only targeting easy victims but also more protected and hardened systems.

What separates C0XMO technically from older Gafgyt variants is the decision to split scanning into a standalone Python script rather than embedding it in the main binary. The script installs requests, paramiko, and beautifulsoup4 via pip and runs 22 functions organized across six categories: worker threads, blacklist management, Telnet exploitation, SSH exploitation, HTTP exploitation, and Android Debug Bridge exploitation. It maintains a blacklist.txt to avoid scanning honeypots and research institutions, and a failed.txt to skip previously unsuccessful targets.

“Unlike traditional botnets, C0XMO isolates its scanning function into an independent Python script.” continues the report. “The malware fetches this script from the same IP address and port—217[.]160[.]125[.]125:15527—that it uses to distribute the main C0XMO binary.”

Keeping the scanner as a separate module lets attackers easily update, replace, or adapt it for new device types without changing the main malware. This makes the botnet more flexible and easier to maintain.

The malware also includes a large set of HTTP exploits. The scanner targets CVE-2021-27137 (the same DD-WRT flaw used for initial access), CVE-2015-2051 in D-Link devices, CVE-2022-35914 in GLPI, AVTECH DVR vulnerabilities including CVE-2025-34054 and CVE-2016-15047, NVMS-9000 flaws, Zyxel SysTools remote code execution, and several others. The ADB module goes after Android devices with exposed debug interfaces, which is a category of vulnerable hardware most enterprise security teams don’t monitor at all.

C0XMO is more advanced than older IoT botnets. It uses modular components, multi-step spreading methods, and a more structured design that makes it flexible and scalable. Separating scanning and infection functions shows a shift toward more efficient and adaptable botnet operations compared to typical Gafgyt malware.

“C0XMO exhibits a considerably more advanced architecture and feature set compared to earlier IoT botnets. Its modular exploitation features, multi-phase propagation methods, and overall design suggest a greater degree of operational sophistication and complexity than typical Gafgyt malware.” concludes the report. “The distinction between its scanning and propagation parts underscores an evolution towards more adaptable and scalable botnet deployment strategies.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, botnet)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/193290/malware/iot-botnet-c0xmo-adds-competitor-killing-capability.html