AUTO-UPDATED

AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network

Researchers at QiAnXin XLab have identified a new malware family called AryStinger that is compromising thousands of legacy routers and NAS devices to create a stealthy reconnaissance proxy network.

Key Points

  • AryStinger has infected at least 4,300 routers, primarily targeting D-Link DIR-850L models equipped with older Realtek RTL819X chips.
  • The malware exploits known vulnerabilities, including CVE-2013-3307 and CVE-2016-5681, to turn devices into nodes for internet scanning and traffic relaying.
  • A secondary strain targets QNAP NAS devices by exploiting CVE-2025-11837, a code injection flaw within the manufacturer's own malware-removal tool.
  • Infected devices are concentrated in South Korea and China, functioning as a distributed infrastructure for attackers to mask their origins during cyber intrusions.
  • Security experts recommend retiring end-of-life hardware that no longer receives firmware updates and disabling remote administration features on all exposed network appliances.

Why it Matters

This campaign highlights the persistent security risk posed by end-of-life networking equipment that remains in use despite lacking modern patches. By repurposing these devices into operational relay boxes, attackers can conduct large-scale reconnaissance and hide their digital footprints, complicating efforts by security teams to trace malicious activity.
Internet Published by info@thehackernews.com (The Hacker News)
Read original