The C0XMO Botnet Exploits a Five-Year-Old DD-WRT Vulnerability, Supports Seven Architectures, and Murders Every Rival Botnet on Your Router — Your Firmware Update Can Wait, Said Nobody Ever

A new botnet variant called C0XMO is exploiting a five-year-old vulnerability in DD-WRT router firmware to compromise devices across seven CPU architectures — and its first order of business upon arrival is to murder every other botnet already living on your router. Discovered by Fortinet researchers, C0XMO is a Gafgyt variant with what Fortinet describes as “a considerably more advanced architecture and feature set compared to earlier IoT botnets.” Translation: the botnet evolved, and it brought a résumé.

🤚 The Open-Palm Infection Report

The vulnerability in question is CVE-2021-27137, a buffer overflow in DD-WRT router firmware caused by insufficient input validation. It requires no authentication. It permits remote code execution. It has been public since 2021. If your router is still running vulnerable firmware, congratulations — you’ve been offering free compute to strangers for half a decade, and the newest tenant just evicted all the previous ones.

Here’s how C0XMO operates:

  • A Python-based scanner sweeps the internet for devices exposed on common ports — SSH, Telnet, HTTP, HTTPS, and others
  • It attempts to brute-force weak credentials on discovered devices
  • Upon access, it detects the CPU architecture of the compromised device
  • It deploys a compatible binary from its multi-architecture arsenal
  • It immediately begins hunting and killing rival malware

The supported architectures include ARM, MIPS, PowerPC, SuperH, x86, x86_64, and others — meaning C0XMO can infect everything from consumer routers and DVRs to video management platforms and Android-based devices. It’s an equal-opportunity parasite.

👐 The Two-Handed Malware Turf War

The most remarkable feature of C0XMO isn’t its infection chain — that’s fairly standard IoT botnet behavior. It’s the housekeeping.

Upon compromising a device, C0XMO scans all running processes to identify competing botnet clients. It then systematically removes them by:

  • Deleting their binaries
  • Removing their cron jobs
  • Clearing their init scripts
  • Disabling their system services
  • Scrubbing their shell profile entries

This is not malware. This is malware with a cleaning service. C0XMO doesn’t want to share your router’s resources with Mirai variants and cryptocurrency miners. It wants exclusive tenancy, and it’s willing to do the digital equivalent of changing the locks, throwing the previous tenant’s belongings on the lawn, and filing a restraining order.

There’s a certain dark professionalism to it. Most IoT botnets coexist in a chaotic soup of competing infections, each degrading performance until the device becomes unusable. C0XMO’s approach is almost considerate — if you ignore the part where it’s commandeered your router for DDoS attacks. Your device will run better than it has in years. It just won’t be working for you.

🌿 The Gentle Awakening

The vulnerability being exploited — CVE-2021-27137 — is five years old. Five years. The patch exists. It has existed since the vulnerability was disclosed. And yet here we are, in the summer of 2026, watching a sophisticated botnet build its empire on firmware that people installed during the Biden administration and never updated.

DD-WRT is popular precisely because it gives users more control over their routers. The irony is that “more control” typically means “flashed it once, felt powerful, never touched it again.” The open-source firmware community is excellent at creating secure software. It is less excellent at teleporting into your home and forcing you to install the update.

C0XMO’s 19 DDoS attack methods — including UDP, TCP, SYN, and ICMP floods, ping of death, and NTP/Memcached amplification — represent a toolkit that would be impressive in a commercial penetration testing product. In a botnet running on your home router, it’s a reminder that the gap between “security tool” and “weapon” is mostly a matter of who clicked the button.

👑 The Gold-Leaf Infrastructure Audit

Fortinet’s recommendation is the same advice the cybersecurity industry has been giving since approximately the invention of the router: keep devices up to date, use unique admin credentials, and disable remote access when not needed.

This advice is correct. It is also, apparently, as effective as posting it on a billboard in a language nobody reads. The IoT security problem was never technical — the patches exist, the best practices are well-documented, and the threat is well-understood. The problem is that nobody updates their router firmware for the same reason nobody flosses as often as their dentist recommends: the consequences are invisible until they’re catastrophic.

C0XMO is what happens when threat actors evolve faster than patch adoption. The vulnerability is half a decade old. The botnet targeting it is brand new, multi-architecture, self-optimizing, and actively eliminating its competition. If your DD-WRT router hasn’t been updated since 2021, it’s not a router anymore. It’s a rental property, and the new tenant just signed a lease you never offered.

“The botnet killed the other botnets, cleaned up after itself, and filed for exclusive occupancy. Your router now has better operational hygiene than it did when you owned it.” — The Slap of Wisdom IoT Forensics Division, updating its own firmware for the first time since the pandemic, just to feel something