More Than 4,000 Legacy Routers Compromised by AryStinger, Turned into Global Attack Proxies for Hackers
ID: 93b82cf1-3637-5597-8fec-b31651ce8499
STIX ID: report--93b82cf1-3637-5597-8fec-b31651ce8499
Feed Name: QiAnXin XLab
This report analyzes the AryStinger malware family that exploits legacy router and NAS vulnerabilities (e.g., CVE-2013-3307, CVE-2016-5681, CVE-2025-11837) to install backdoors (dropbear/gs-netcat), create distributed scanning Executors, perform domain/IP/subdomain brute forcing, proxy/tunnel traffic, and execute remote payloads; it documents technical behavior, propagation scripts, C2/downloader domains, sample hashes, and an observed infection footprint of at least ~4,300 RTL819X devices worldwide.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
