logo

AryStinger Botnet Uses Intranet Scanning and Traffic Tunneling to Hide Attacker Activity

ID: 2e340c3a-a929-55dc-9e28-2feafa737fef

STIX ID: report--2e340c3a-a929-55dc-9e28-2feafa737fef

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Mayura Kathir

...
...

AryStinger is a newly analyzed botnet that weaponizes outdated RTL819X-based routers and NAS devices by exploiting long-known vulnerabilities (e.g., CVE-2013-3307, CVE-2016-5681, CVE-2025-11837) to perform distributed scanning, intranet discovery, and traffic tunneling. The family uses compact C builds for routers and a Go "Standard" variant for NAS, employs a controller/Executor model with Protobuf-serialized, XOR-obfuscated communications over HTTP/HTTPS, and deploys lightweight backdoors (dropbear, gs-netcat, nat_tunnel) to maintain persistence; QiAnXin XLab telemetry found over 4,300 infected RTL819X routers concentrated in South Korea and China and identified hardcoded C2 domains (dybic.ajb8.com, opi7.com). Recommended mitigations include replacing or isolating end-of-life devices, applying patches where available, auditing edge devices for IOCs (C2 domains, dropbear ports, /tmp/bin artifacts), and enabling egress filtering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.