← Back to Feed

Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO

June 3, 2026 · Fortinet Threat Research · Severity: HIGH

FortiGuard Labs has identified C0XMO, a new variant of the Gafgyt malware, which is actively exploiting vulnerabilities in DD-WRT firmware to propagate across multiple architectures and expand IoT botnet infections. The malware targets routers running DD-WRT, a popular open-source firmware, by exploiting CVE-2023-1389, a command injection vulnerability. C0XMO is designed to infect devices across various architectures, including ARM, MIPS, and x86, enabling it to compromise a wide range of IoT devices. Once infected, these devices are recruited into a botnet, which can be used for distributed denial-of-service (DDoS) attacks, cryptocurrency mining, or other malicious activities. The propagation of C0XMO poses a significant threat to both individual users and organizations relying on IoT devices. Affected devices include routers, cameras, and other smart devices, which are often inadequately secured and rarely updated. The malware’s ability to exploit a known vulnerability underscores the importance of timely patching and robust cybersecurity practices. Fortinet emphasizes the need for organizations to monitor their networks for unusual activity, update firmware regularly, and implement strong security measures to mitigate the risk of infection. The emergence of C0XMO highlights the evolving sophistication of IoT-targeting malware and the growing challenges in securing interconnected devices.

FortiGuard Labs analyzes C0XMO, a new Gafgyt variant leveraging DD-WRT exploitation and multi-architecture propagation to expand IoT botnet infections.

      

Key Takeaways

  • FortiGuard Labs analyzes C0XMO, a new Gafgyt variant leveraging DD-WRT exploitation and multi-architecture.
  • FortiGuard Labs analyzes C0XMO, a new Gafgyt variant leveraging DD-WRT exploitation and multi-architecture propagation to expand IoT botnet infections.
☕ Buy a Coffee