logo

隐形毒刺:超4000台老旧路由器遭AryStinger入侵,沦为黑客全球攻击跳板

ID: 121d82d2-a3c9-5ca7-8cce-d193fe8f01e3

STIX ID: report--121d82d2-a3c9-5ca7-8cce-d193fe8f01e3

Feed Name: QiAnXin XLab

Threat Score
75/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Alex.Turing

...
...

This report analyzes the AryStinger malware family that actively compromises legacy RTL819X-based routers and NAS systems using historical and recent vulnerabilities (CVE-2013-3307, CVE-2016-5681, CVE-2025-11837). AryStinger deploys C and Go implants that communicate with C2 servers using Protobuf plus simple XOR/Gzip+XOR, establish persistent backdoors (dropbear/gs-netcat), provide distributed scanning, tunneling and remote code execution (including source-level payloads), and has infected at least ~4,300 routers worldwide; the report includes domains, IPs, downloader URLs and file hashes and recommends replacing/updating old routers and using the provided IOCs for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.