Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AryStinger Malware Targets Legacy Routers for Proxy Network

AryStinger Malware Targets Legacy Routers for Proxy Network

Posted on June 22, 2026 By CWS

The AryStinger malware is exploiting outdated home routers, repurposing them into a distributed reconnaissance and proxy network. According to QiAnXin’s XLab, this malware has already infected at least 4,300 routers, with numbers continuing to rise.

Understanding AryStinger’s Functionality

Unlike typical botnets used for DDoS attacks, AryStinger is designed for pre-intrusion activity. The infected routers scan online resources, identify services, map subdomains, and relay traffic to mask the true origin of the attacker. These routers serve as nodes in a network, providing a veil of anonymity for cybercriminals.

The campaign targets routers with Realtek’s RTL819X chips, prevalent between 2012 and 2015. The spread began on March 12, 2026, from the IP address 107.150.106.14. The malware exploits older vulnerabilities, specifically CVE-2013-3307 in Linksys and CVE-2016-5681 in D-Link models, primarily affecting D-Link DIR-850L devices in regions like South Korea and China.

Expansion to QNAP NAS Devices

On April 26, 2026, a variant targeting QNAP NAS devices emerged using CVE-2025-11837, a vulnerability in QNAP’s Malware Remover tool. This vulnerability was demonstrated at Pwn2Own Ireland in 2025 and addressed later that year. However, the malware leverages the tool’s flaw to infiltrate systems, although the extent of NAS infections remains unquantified.

The malware is deployed in two versions: a lightweight C build for routers focusing on DNS scanning and traffic tunneling, and a more complex Go build for NAS devices that performs extensive network reconnaissance. These builds allow attackers to utilize compromised devices without compiling binaries for each target.

Implications and Precautions

The structure of this campaign is reminiscent of previous espionage operations dismantled by authorities, such as the FBI’s takedown of 5socks and Anyproxy services. These services used compromised routers as residential proxies, similar to AryStinger’s approach.

Though the perpetrators behind AryStinger remain unidentified, its reliance on outdated hardware and software vulnerabilities is clear. Users of affected devices should monitor for unusual outbound connections and check for unauthorized binaries or processes. The recommended course of action is to retire unsupported routers and disable remote administration features to mitigate future risks.

Maintaining up-to-date firmware and replacing legacy hardware are crucial steps in securing networks against threats like AryStinger. As cyber threats evolve, staying informed and proactive is essential for protecting digital infrastructure.

The Hacker News Tags:AryStinger, Cybersecurity, D-Link, IoT security, legacy routers, Linksys, Malware, proxy network, QNAP, Realtek RTL819X, Reconnaissance

Post navigation

Previous Post: INTERPOL Warns of Rising Cyber Threats in Asia-Pacific
Next Post: Hackers Use Fake Google Ads to Deploy Malware

Related Posts

New Win-DDoS Flaws Let Attackers Turn Public Domain Controllers into DDoS Botnet via RPC, LDAP New Win-DDoS Flaws Let Attackers Turn Public Domain Controllers into DDoS Botnet via RPC, LDAP The Hacker News
Chinese Hackers Murky, Genesis, and Glacial Panda Escalate Cloud and Telecom Espionage Chinese Hackers Murky, Genesis, and Glacial Panda Escalate Cloud and Telecom Espionage The Hacker News
Cisco Confirms Active Exploits Targeting ISE Flaws Enabling Unauthenticated Root Access Cisco Confirms Active Exploits Targeting ISE Flaws Enabling Unauthenticated Root Access The Hacker News
Lumen Technologies Reinvents Exposure Management Strategy Lumen Technologies Reinvents Exposure Management Strategy The Hacker News
Cyber Group Exploits Brazilian Sites for Betting Promotions Cyber Group Exploits Brazilian Sites for Betting Promotions The Hacker News
AI-Powered Zero-Day Exploit Bypasses 2FA Security AI-Powered Zero-Day Exploit Bypasses 2FA Security The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Integration: A Must for Business Success
  • Guarding AI Models Against Sophisticated Ransomware Attacks
  • AI Security Breach: Hugging Face Incident Analysis
  • CISA Alerts on Linux Kernel Flaws Under Active Attack
  • TigerByte Cyber Launches with $3M Funding to Enhance Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Integration: A Must for Business Success
  • Guarding AI Models Against Sophisticated Ransomware Attacks
  • AI Security Breach: Hugging Face Incident Analysis
  • CISA Alerts on Linux Kernel Flaws Under Active Attack
  • TigerByte Cyber Launches with $3M Funding to Enhance Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark