AUTO-UPDATED

4,300+ Outdated Routers Hijacked in Stealthy Spy Infrastructure by AryStinger malware

QiAnXin’s XLab researchers have identified AryStinger, a sophisticated malware campaign utilizing thousands of outdated routers and NAS devices to build a covert, distributed infrastructure for global intrusion reconnaissance.

Key Points

  • AryStinger targets end-of-life hardware, specifically Realtek RTL819X-based routers and QNAP NAS devices, using long-standing vulnerabilities.
  • The botnet currently comprises over 4,300 infected devices, with D-Link models accounting for approximately 75% of the identified router pool.
  • Infected nodes act as "Executors" that perform parallelized tasks like port scanning, service identification, and subdomain enumeration for the attacker.
  • The malware features a modular design, including a C-based build for routers and a Go-based build for NAS devices that supports dynamic script execution.
  • Primary infections are concentrated in South Korea (48%) and China (32%), with additional activity detected in Sweden, Malaysia, and Singapore.

Why it Matters

This campaign highlights the significant security risks posed by legacy hardware that no longer receives firmware updates, effectively turning forgotten devices into permanent, invisible attack springboards. By leveraging these "n-day" vulnerabilities, attackers can establish a massive, low-detection infrastructure capable of conducting large-scale reconnaissance against critical networks.
Securityaffairs.com Published by Pierluigi Paganini
Read original