logo

4,300+ Outdated Routers Hijacked in Stealthy Spy Infrastructure by AryStinger malware

ID: 9032d713-9f61-5ddf-aef6-ad2a50dbd6dc

STIX ID: report--9032d713-9f61-5ddf-aef6-ad2a50dbd6dc

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Pierluigi Paganini

...
...

QiAnXin XLab reported the AryStinger campaign that has hijacked 4,300+ outdated RTL819X-based routers (predominantly D-Link DIR-850L) using older CVEs (CVE-2013-3307, CVE-2016-5681) and a later Go build exploiting CVE-2025-11837 against NAS devices; infected devices act as Executors to perform distributed reconnaissance (DNS/subdomain brute force, port/service scanning, TLS fingerprinting), tunnel traffic to hide operator location, and accept attacker-supplied scripts, while communicating with C2/download infrastructure including ajb8.com, dataexplore.cc, and dataexplore.co; recommended mitigation includes checking for outbound C2 connections, unexpected binaries in /tmp/bin, processes named syswapd0h/syswapd0w, and retiring unpatched legacy routers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.