C0XMO botnet spreads via DD-WRT router flaw, kills rival malware
2026-06-07T19:23:31Z•9f9855d5350e129f5d0adc6b628568b7ec85527a1b2304e707d874b3edc24be5
APT UNC5221C0XMOCisco SD-WANDD-WRTEverest Forms ProMagecartMicrosoft 365SolarWinds Serv-Ubotnetcredential theftcryptominerdata breachexposed ICS/ATG systemspayment card theftransom/extortionrouterssocial engineeringsupply chainzero-day
What happened
Feed of June 4–7, 2026 BleepingComputer reports covering multiple active threats: a new Gafgyt variant (C0XMO) exploiting a DD‑WRT router flaw and spreading across CPU architectures; social‑engineering extortion by the Silent Ransom Group against law firms; active exploitation of a critical Everest Forms Pro vulnerability (CVE-2026-3300) enabling full WordPress site takeover; suspicious credential‑harvesting Polyfill login prompts on major websites; CISA advisories about attackers exploiting a recently patched SolarWinds Serv-U flaw to crash servers; Cisco reporting an actively exploited SD‑W‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 9f9855d5350e129f5d0adc6b628568b7ec85527a1b2304e707d874b3edc24be5
- Enrichment time
- 2026-06-07T19:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.