Researchers at QiAnXin XLab have identified a new malware family called AryStinger that is compromising thousands of legacy routers and NAS devices to create a stealthy reconnaissance proxy network.
Key Points
- AryStinger has infected at least 4,300 routers, primarily targeting D-Link DIR-850L models equipped with older Realtek RTL819X chips.
- The malware exploits known vulnerabilities, including CVE-2013-3307 and CVE-2016-5681, to turn devices into nodes for internet scanning and traffic relaying.
- A secondary strain targets QNAP NAS devices by exploiting CVE-2025-11837, a code injection flaw within the manufacturer's own malware-removal tool.
- Infected devices are concentrated in South Korea and China, functioning as a distributed infrastructure for attackers to mask their origins during cyber intrusions.
- Security experts recommend retiring end-of-life hardware that no longer receives firmware updates and disabling remote administration features on all exposed network appliances.