AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
ID: 7da34a1a-cfab-513e-8e2d-f7d4794ab97e
STIX ID: report--7da34a1a-cfab-513e-8e2d-f7d4794ab97e
Feed Name: The Hacker News
A newly observed malware family called AryStinger is actively infecting thousands of end-of-life routers (RTL819X) and has a later strain targeting QNAP NAS, exploiting legacy CVEs (CVE-2013-3307, CVE-2016-5681) and a 2025 QNAP code-injection flaw (CVE-2025-11837). Infected devices act as footprinting nodes and relays—scanning, tunneling traffic, executing operator-supplied code, and reporting to HTTP/HTTPS C2—enabling large-scale reconnaissance and proxying while remaining stealthy; XLab reports ~4,300 router infections concentrated in South Korea and China and provides IOCs and detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
