AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
ID: 4a39ec43-ea0a-5502-8fd5-ea64fb67e4d3
STIX ID: report--4a39ec43-ea0a-5502-8fd5-ea64fb67e4d3
Feed Name: CosmicBytez Labs
**AryStinger** is a newly observed malware family that has infected ~4,300 legacy routers and QNAP NAS devices (notably D-Link DIR-850L and RTL819X-based hardware) to create a distributed reconnaissance and proxy network that masks attacker origins; the campaign exploits multiple CVEs (including CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837), uses two distinct C and Go builds with obfuscated communications and remote execution capabilities, and provides C2 domains and other IoCs alongside mitigation guidance such as replacing end-of-life hardware and blocking known C2 domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
