QiAnXin’s XLab researchers have identified AryStinger, a sophisticated malware campaign utilizing thousands of outdated routers and NAS devices to build a covert, distributed infrastructure for global intrusion reconnaissance.
Key Points
- AryStinger targets end-of-life hardware, specifically Realtek RTL819X-based routers and QNAP NAS devices, using long-standing vulnerabilities.
- The botnet currently comprises over 4,300 infected devices, with D-Link models accounting for approximately 75% of the identified router pool.
- Infected nodes act as "Executors" that perform parallelized tasks like port scanning, service identification, and subdomain enumeration for the attacker.
- The malware features a modular design, including a C-based build for routers and a Go-based build for NAS devices that supports dynamic script execution.
- Primary infections are concentrated in South Korea (48%) and China (32%), with additional activity detected in Sweden, Malaysia, and Singapore.