C0XMO botnet spreads via DD-WRT router flaw, kills rival malware

2026-06-07T19:23:31Z9f9855d5350e129f5d0adc6b628568b7ec85527a1b2304e707d874b3edc24be5
APT UNC5221C0XMOCisco SD-WANDD-WRTEverest Forms ProMagecartMicrosoft 365SolarWinds Serv-Ubotnetcredential theftcryptominerdata breachexposed ICS/ATG systemspayment card theftransom/extortionrouterssocial engineeringsupply chainzero-day

What happened

Feed of June 4–7, 2026 BleepingComputer reports covering multiple active threats: a new Gafgyt variant (C0XMO) exploiting a DD‑WRT router flaw and spreading across CPU architectures; social‑engineering extortion by the Silent Ransom Group against law firms; active exploitation of a critical Everest Forms Pro vulnerability (CVE-2026-3300) enabling full WordPress site takeover; suspicious credential‑harvesting Polyfill login prompts on major websites; CISA advisories about attackers exploiting a recently patched SolarWinds Serv-U flaw to crash servers; Cisco reporting an actively exploited SD‑W‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
9f9855d5350e129f5d0adc6b628568b7ec85527a1b2304e707d874b3edc24be5
Enrichment time
2026-06-07T19:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · C0XMO botnet spreads via DD-WRT router flaw, kills rival malware · Baitaphish