#gafgyt
Gafgyt Malware Broadens Its Scope in Recent Attacks
Gafgyt Malware Broadens Its Scope in Recent Attacks
Our researchers identified threat actors exploiting misconfigured Docker servers to spread the Gafgyt malware. This threat traditionally targets IoT devices; this new tactic signals a change in its…
www.trendmicro.com
December 5, 2024 at 2:12 AM
A new variant of the Gafgyt botnet called C0XMO is targeting DD-WRT router firmware and can move to other device types with various CPU architectures.
C0XMO botnet spreads via DD-WRT router flaw, kills rival malware
A new variant of the Gafgyt botnet called C0XMO is targeting DD-WRT router firmware and can move to other device types with various CPU architectures.
www.bleepingcomputer.com
June 7, 2026 at 2:18 PM
New Hpingbot botnet spotted

-written in Go
-used for DDoS attacks
-abuses hping3 tool to launch the attacks
-unique codebase, not Mirai or Gafgyt clone

nsfocusglobal.com/hpingbot-a-n...
Hpingbot: A New Botnet Family Based on Pastebin Payload Delivery Chain and Hping3 DDoS Module - NSFOCUS, Inc., a global network and cyber security leader, protects enterprises and carriers from advanc...
Overview In June 2025, NSFOCUS Fuying Lab Global Threat Hunting System detected that a new botnet family developed based on Go language was spreading on a large scale, and continued to iterate version...
nsfocusglobal.com
July 6, 2025 at 4:41 PM
#Gafgyt Malware Broadens Its Scope in Recent Attacks
Gafgyt Malware Broadens Its Scope in Recent Attacks
Our researchers identified threat actors exploiting misconfigured Docker servers to spread the Gafgyt malware. This threat traditionally targets IoT devices; this new tactic signals a change in its…
buff.ly
December 4, 2024 at 12:30 PM
Alert: New Gafgyt variant C0XMO exploits DD-WRT vulnerability, targeting multiple Linux architectures. Update your firmware and secure your devices now! #CyberSecurity #IoT #Linux #Botnet Link: thedailytechfeed.com/new-gafgyt-c...
June 6, 2026 at 3:34 PM
C0XMO Botnet Expands Aggressively, Turning Vulnerable DD-WRT Routers into a Growing Cyber Army + Video

Introduction The threat landscape surrounding Internet-connected devices continues to evolve as attackers refine old malware families with new capabilities. Security researchers have recently…
C0XMO Botnet Expands Aggressively, Turning Vulnerable DD-WRT Routers into a Growing Cyber Army + Video
Introduction The threat landscape surrounding Internet-connected devices continues to evolve as attackers refine old malware families with new capabilities. Security researchers have recently highlighted the emergence of C0XMO, a modular botnet derived from the notorious Gafgyt malware family. The campaign focuses heavily on compromised DD-WRT routers, exploiting known vulnerabilities and weak authentication mechanisms to silently recruit devices into a large-scale malicious network.
undercodenews.com
June 7, 2026 at 6:16 PM
There already is a patch for the flaw, tracked as CVE-2023-1389, found in the Web management interface of the TP-Link Archer AX21 (AX1800) Wi-Fi router and affecting devices Version 1.1.4 Build 20230219 or prior. www.darkreading.com/ics-ot-secur...
Various Botnets Pummel Year-Old TP-Link Flaw in IoT Attacks
Moobot, Miori, AGoent, and a Gafgyt variant have joined the infamous Mirai botnet in attacking unpatched versions of vulnerable Wi-Fi routers.
www.darkreading.com
April 18, 2024 at 10:56 AM
IoT Botnet C0XMO Adds Competitor-Killing Capability

C0XMO is a new Gafgyt botnet variant exploiting old router flaws, spreading across IoT devices, killing rivals, and enabling large-scale DDoS attacks. In March 2026, FortiGuard Labs discovered a new variant of the Gafgyt botnet,…
#hackernews #news
IoT Botnet C0XMO Adds Competitor-Killing Capability
C0XMO is a new Gafgyt botnet variant exploiting old router flaws, spreading across IoT devices, killing rivals, and enabling large-scale DDoS attacks. In March 2026, FortiGuard Labs discovered a new variant of the Gafgyt botnet, dubbed C0XMO, which is noticeably more capable than its predecessors. The malware spreads through CVE-2021-27137, a stack buffer overflow in […]
securityaffairs.com
June 8, 2026 at 10:41 PM
C0XMO Unleashed: The New Gafgyt Botnet Variant Quietly Taking Over Linux Devices Across the Internet + Video

Introduction: A Familiar Threat Returns in a More Dangerous Form The Linux threat landscape has entered another turbulent chapter with the emergence of C0XMO, a newly discovered variant of…
C0XMO Unleashed: The New Gafgyt Botnet Variant Quietly Taking Over Linux Devices Across the Internet + Video
Introduction: A Familiar Threat Returns in a More Dangerous Form The Linux threat landscape has entered another turbulent chapter with the emergence of C0XMO, a newly discovered variant of the infamous Gafgyt botnet. While Gafgyt has been a persistent menace for years, this latest evolution demonstrates how cybercriminals continue to refine and modernize old malware families to maximize their reach and destructive capabilities.
undercodenews.com
June 5, 2026 at 10:58 AM
C0XMO botnet spreads via DD-WRT router flaw, kills rival malware

A new variant of the Gafgyt botnet called C0XMO is targeting DD-WRT router firmware and can move to other device types with various CPU architectures. [...]
#hackernews #news
C0XMO botnet spreads via DD-WRT router flaw, kills rival malware
A new variant of the Gafgyt botnet called C0XMO is targeting DD-WRT router firmware and can move to other device types with various CPU architectures. [...]
www.bleepingcomputer.com
June 8, 2026 at 3:01 PM
C0XMO: il malware che infetta i server e stermina tutti gli altri malware

📌 Link all'articolo : www.redhotcyber.com/post/c0xmo-i...

A cura di Carolina Vivianti

#redhotcyber #news #cybersecurity #hacking #malware #botnet #ddos #gafgyt #c0xmo #ddwrt
June 9, 2026 at 12:31 PM
IoT Botnet C0XMO Adds Competitor-Killing Capability
IoT Botnet C0XMO Adds Competitor-Killing Capability
C0XMO is a new Gafgyt botnet variant exploiting old router flaws, spreading across IoT devices, killing rivals, and enabling large-scale DDoSs
securityaffairs.com
June 8, 2026 at 7:51 AM
C0XMO botnet spreads via DD-WRT router flaw, kills rival malware
C0XMO botnet spreads via DD-WRT router flaw, kills rival malware
A new variant of the Gafgyt botnet called C0XMO is targeting DD-WRT router firmware and can move to other device types with various CPU architectures.
www.bleepingcomputer.com
June 7, 2026 at 2:46 PM
C0XMO botnet spreads via DD-WRT router flaw, kills rival malware
www.bleepingcomputer.com/news/securit...
C0XMO botnet spreads via DD-WRT router flaw, kills rival malware
A new variant of the Gafgyt botnet called C0XMO is targeting DD-WRT router firmware and can move to other device types with various CPU architectures.
www.bleepingcomputer.com
June 8, 2026 at 11:37 AM
MalwareBazaar will now parse shell scripts automatically and will try to identify any payload URLs present in it 📄🔍👁️ This will make your life easier when hunting for Linux/Unix malware such as #Mirai and #Gafgyt 💪

Here's an example:
👉 bazaar.abuse.ch/sample/ec46f...
December 30, 2024 at 11:23 AM
📌 Sharp Increase in Automated Attacks by Botnets Targeting PHP Servers, IoT Devices, and Cloud Gateways https://www.cyberhub.blog/article/14995-sharp-increase-in-automated-attacks-by-botnets-targeting-php-servers-iot-devices-and-cloud-gateways
Sharp Increase in Automated Attacks by Botnets Targeting PHP Servers, IoT Devices, and Cloud Gateways
Cybersecurity researchers have reported a significant rise in automated attacks targeting PHP servers, IoT devices, and cloud gateways by botnets such as Mirai, Gafgyt, and Mozi. According to the Qualys Threat Research Unit (TRU), these campaigns exploit known CVEs and cloud misconfigurations to take control of exposed systems and expand botnet networks. The technical implications of these attacks are substantial. Automated attacks allow for rapid exploitation of vulnerabilities at scale, leading to widespread compromises. The use of known CVEs highlights the importance of timely patching and proper configuration management. The impact on the cybersecurity landscape includes potential data breaches, service disruptions, and the propagation of botnets, which can be used for various malicious activities, including DDoS attacks. For cybersecurity professionals, this underscores the need for robust patch management processes and regular vulnerability assessments. Organizations should prioritize patching known vulnerabilities and reviewing cloud configurations to mitigate risks. Additionally, continuous monitoring for signs of compromise and having a well-defined incident response plan are crucial. Expert insights suggest that the persistence and evolution of botnets like Mirai, Gafgyt, and Mozi pose ongoing threats. These botnets are known for their ability to spread quickly and cause significant damage. Therefore, proactive measures and a strong security posture are essential to defend against these automated attacks.
www.cyberhub.blog
October 30, 2025 at 4:40 PM
IoT Under Siege: C0XMO Malware and GitHub Supply Chain Weakness Signal a New Wave of Silent Cyber Warfare + Video

Global Security Flashpoint Introduction The cybersecurity landscape has once again been shaken by a dual revelation that highlights how fragile modern digital infrastructure has…
IoT Under Siege: C0XMO Malware and GitHub Supply Chain Weakness Signal a New Wave of Silent Cyber Warfare + Video
Global Security Flashpoint Introduction The cybersecurity landscape has once again been shaken by a dual revelation that highlights how fragile modern digital infrastructure has become. On one side, FortiGuard Labs has uncovered a newly evolving botnet strain known as C0XMO, derived from the infamous Gafgyt family, actively exploiting a known vulnerability in DD-WRT routers. On the other side, a separate but equally alarming issue surfaced in a GitHub Actions workflow tied to Anthropic’s Claude Code, revealing how a single malicious input could potentially compromise public repositories in a supply chain-style attack.
undercodenews.com
June 5, 2026 at 3:06 AM
デフォルトの資格情報の更新を。
"このボットネットは、Mirai と Bashlite (別名Gafgyt、Lizkebabなど) に由来するマルウェアにより構成されたボットネットと考えられます。"

2024年末からのDDoS攻撃被害と関連性が疑われるIoTボットネットの大規模な活動を観測
www.trendmicro.com/ja_jp/resear...
January 6, 2025 at 2:24 PM
New Gafgyt Variant C0XMO Exploits DD-WRT Flaw to Spread Across Platforms

FortiGuard Labs found a new Gafgyt variant, C0XMO, exploiting a DD-WRT router vulnerability. It targets Japanese tech firms, spreads across multiple architectures, and separates scanning into a Python script.
July 15, 2026 at 9:13 AM