AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
Reported exploitedLinksys routers (RTL819X-based models)D-Link DIR-850L (DIR-850L largely targeted)Our summary
QiAnXin’s XLab reports that its AryStinger malware has infected at least 4,300 legacy routers and repurposes them for pre-intrusion reconnaissance and proxying (scanning, service fingerprinting, subdomain enumeration, tunneling, and on-demand command execution). The activity targets routers using Realtek RTL819X chips and exploits older, already-public issues: CVE-2013-3307 (Linksys) and CVE-2016-5681 (D-Link), with the majority of infected devices attributed to D-Link models such as DIR-850L. A separate strain was also observed against QNAP systems via CVE-2025-11837 in QNAP's Malware Remover, underscoring how unsupported networking gear can be used to build resilient attacker infrastructure.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.