securityonline.info 6/10/2026, 9:10:00 AM · external

COXMO botnet hijacks devices via CVE-2021-27137 flaw worldwide

COXMO botnet hijacks devices via CVE-2021-27137 flaw worldwide
CyberSIXT Evidence Panel
Primary Source fortinet.com
CISA KEV Not in KEV
Patch Patch Status Unknown

THE page details a critical alert regarding the COXMO botnet variant, which poses a serious threat to internet-connected infrastructure globally. Researchers note the botnet employs advanced tactics including modular propagation to exploit older software vulnerabilities, particularly the CVE-2021-27137 stack buffer overflow flaw.

After initial access, the malware installs itself persistently, sets up automated processes, eliminates rival threats, and can conduct distributed denial-of-service attacks using sophisticated techniques. The COXMO variant also features independent lateral movement capabilities, utilizing external scripts to expand its reach across vulnerable devices.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline