logo

More Than 4,000 Legacy Routers Compromised by AryStinger, Turned into Global Attack Proxies for Hackers

ID: 93b82cf1-3637-5597-8fec-b31651ce8499

STIX ID: report--93b82cf1-3637-5597-8fec-b31651ce8499

Feed Name: QiAnXin XLab

Threat Score
78/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Alex.Turing

...
...

This report analyzes the AryStinger malware family that exploits legacy router and NAS vulnerabilities (e.g., CVE-2013-3307, CVE-2016-5681, CVE-2025-11837) to install backdoors (dropbear/gs-netcat), create distributed scanning Executors, perform domain/IP/subdomain brute forcing, proxy/tunnel traffic, and execute remote payloads; it documents technical behavior, propagation scripts, C2/downloader domains, sample hashes, and an observed infection footprint of at least ~4,300 RTL819X devices worldwide.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.