Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO
June 3, 2026 · Fortinet Threat Research · Severity: HIGH
FortiGuard Labs has identified a new Gafgyt malware variant, C0XMO, which spreads across multiple platforms by exploiting vulnerabilities in DD-WRT routers and targeting IoT devices. The malware uses cross-platform propagation techniques, including multi-architecture payloads, to infect systems running on ARM, MIPS, and x86 architectures. This allows it to expand botnet infections rapidly, compromising routers and IoT devices to launch DDoS attacks or further malware distribution. The attack primarily affects poorly secured IoT devices and routers running outdated DD-WRT firmware. C0XMO’s ability to propagate across different hardware architectures makes it particularly dangerous, as it can infect a wide range of devices. This highlights the growing threat of IoT botnets and the need for timely firmware updates and strong security measures to prevent exploitation. Fortinet advises organizations to patch vulnerable systems and monitor for suspicious network activity.
FortiGuard Labs analyzes C0XMO, a new Gafgyt variant leveraging DD-WRT exploitation and multi-architecture propagation to expand IoT botnet infections.
Key Takeaways
- FortiGuard Labs identified a new Gafgyt malware variant called C0XMO that spreads across multiple platforms.
- The malware exploits vulnerabilities in DD-WRT routers and targets IoT devices.
- C0XMO uses cross-platform propagation techniques including multi-architecture payloads.