Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AryStinger Botnet Compromises 4,300 Routers for Global Proxy

AryStinger Botnet Compromises 4,300 Routers for Global Proxy

Posted on June 23, 2026 By CWS

A newly surfaced cyber threat known as the AryStinger botnet has stealthily commandeered over 4,300 routers worldwide, covertly transforming them into attack proxies. This operation leverages longstanding vulnerabilities to establish a network for reconnaissance, remarkable for its ability to evade standard security measures.

Exploitation of Old Vulnerabilities

The AryStinger campaign was first detected on March 12, 2026, when a suspicious IP was flagged by a threat monitoring system. It was disseminating malware via router vulnerabilities CVE-2013-3307 and CVE-2016-5681, affecting certain Linksys and D-Link models. These routers, due to their outdated security, allowed the malware to remain undetected by major scanning platforms.

Research by Qianxin XLab, shared with Cyber Security News, unveiled this attack focusing on routers built with RTL819X chips, prevalent from 2012 to 2015. The team later found a sample targeting NAS devices via another vulnerability, CVE-2025-11837, leading to the identification of the AryStinger malware family.

Functionality Beyond Conventional Botnets

Unlike typical botnets used for DDoS attacks or cryptocurrency mining, AryStinger is crafted for strategic data gathering and as a springboard for further network intrusions. Compromised routers act as ‘ghost nodes,’ masking attackers’ locations while probing other networks.

A hardcoded encryption key within AryStinger, reading “sh_#@!_2024_secret,” indicates the campaign’s potential activity since 2024. The full extent of this operation remains uncertain, as current infection data primarily covers RTL819X routers, with NAS device impacts still being assessed.

Technical Specifics and Geographic Impact

Once a router is infected, it communicates with a command server, transmitting encrypted data like MAC and IP addresses, system versions, and CPU architecture. Each device is assigned a unique Executor ID, integrating it into the botnet for distributed reconnaissance tasks.

The botnet functionality includes port scanning, service identification, and traffic tunneling, effectively concealing the attackers’ identities. The majority of affected devices are D-Link DIR-850L routers, with South Korea and China being the most impacted countries.

AryStinger exists in two versions: a C-written RTL819X variant for older routers, and a Go-written standard version for NAS devices. These variants facilitate persistent backdoors, enabling attackers to maintain long-term access to compromised systems.

Protective Measures and Recommendations

Security experts advise users to scrutinize their network traffic for connections to identified threat domains and check for unknown files or processes on their devices. Outdated router firmware should prompt immediate device replacement or disconnection to mitigate risks.

Overall, the AryStinger botnet’s intricate design and global reach underscore the critical need for robust cybersecurity practices and timely updates to safeguard network infrastructure.

Cyber Security News Tags:AryStinger, Botnet, CVE-2013-3307, CVE-2016-5681, Cybersecurity, D-Link, internet security, Linksys, Malware, NAS devices, network security, network traffic, Qianxin XLab, router vulnerabilities, RTL819X series

Post navigation

Previous Post: Remcos RAT Hidden in GST Note Targets Indian Users
Next Post: Data Breach Impacts Cybersecurity Firms via Klue Integration

Related Posts

INJ3CTOR3 Hackers Exploit FreePBX Systems with Six-Layer Tactics INJ3CTOR3 Hackers Exploit FreePBX Systems with Six-Layer Tactics Cyber Security News
Wing FTP Server Vulnerability Actively Exploited Wing FTP Server Vulnerability Actively Exploited Cyber Security News
CredShields Enhances OWASP 2026 Smart Contract Security CredShields Enhances OWASP 2026 Smart Contract Security Cyber Security News
DPRK IT Workers Using Code-Sharing Platforms to Secure New Remote Jobs DPRK IT Workers Using Code-Sharing Platforms to Secure New Remote Jobs Cyber Security News
NVIDIA Triton Vulnerability Let Attackers Trigger DoS Attack Using Malicious Payload NVIDIA Triton Vulnerability Let Attackers Trigger DoS Attack Using Malicious Payload Cyber Security News
Hackers Exploited 73 0-Day Vulnerabilities and Earned ,024,750 Hackers Exploited 73 0-Day Vulnerabilities and Earned $1,024,750 Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Prinz Eugen Ransomware Utilizes RemotePC for Attacks
  • Data Breach Impacts Cybersecurity Firms via Klue Integration
  • AryStinger Botnet Compromises 4,300 Routers for Global Proxy
  • Remcos RAT Hidden in GST Note Targets Indian Users
  • Malware Targets Windows via Deceptive npm Package

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Prinz Eugen Ransomware Utilizes RemotePC for Attacks
  • Data Breach Impacts Cybersecurity Firms via Klue Integration
  • AryStinger Botnet Compromises 4,300 Routers for Global Proxy
  • Remcos RAT Hidden in GST Note Targets Indian Users
  • Malware Targets Windows via Deceptive npm Package

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark