We are sharing information regarding the C0XMO botnet, a new Gafgyt variant targeting DD-WRT router firmware.
■ Overview C0XMO exploits vulnerabilities in DD-WRT (including CVE-2021-2) to spread across various CPU architectures (ARM, MIPS, x86, etc.). It is designed for modular updates and is primarily used to launch large-scale DDoS attacks using 19 different methods.
■ Scope - Routers running DD-WRT firmware - Vulnerable DVRs, video management platforms, and Android-based devices
■ Mitigation Steps 1. Update DD-WRT firmware to the latest patched version immediately. 2. Restrict external access to router management interfaces (Web UI) and enforce VPN access if necessary. 3. Monitor network traffic for anomalies indicative of DDoS activity (e.g., UDP/TCP/SYN floods).