Find notable cyber news and cases, enriched with sources, timelines, and signals.

AryStinger legacy-router reconnaissance and proxy network

Malware Activity
First reported
Last updated
Happening score
H score 61
1 unique sources, 1 articles

Summary

Hide ▲

The AryStinger malware family is building a distributed reconnaissance and proxy network from legacy routers and NAS appliances, expanding a covert relay layer that helps operators scan and hide their origin. It now affects at least 4,300 infected routers and the pool is still growing. The activity matters because infected devices can fingerprint services, enumerate subdomains, tunnel traffic, and run attacker commands on demand. A second strain extends the operation to QNAP NAS boxes through CVE-2025-11837.

Related Happenings

Russian FSB Center 16 router intrusion campaign

Campaign
H score40 First: 13.07.2026 12:32 Last: 13.07.2026 12:32 Sources 1

About this happening: A Russian FSB Center 16 campaign is targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks, raising the risk of device takeo...

AryStinger legacy-router and QNAP NAS reconnaissance campaign

Campaign
H score72 First: 22.06.2026 09:57 Last: 22.06.2026 09:57 Sources 1

How related: A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network, not the DDoS botnet these devices usually end up in.

About this happening: The AryStinger campaign is turning legacy routers and QNAP NAS boxes into a distributed reconnaissance and proxy network, creating a stealth relay layer for intrus...

AryStinger botnet turns outdated routers into proxy executors

Malware Activity
H score60 First: 21.06.2026 17:14 Last: 21.06.2026 17:14 Sources 1

About this happening: The AryStinger botnet is compromising more than 4,000 outdated routers and converting them into proxy executors for malicious traffic, expanding attacker reach and int...

Popa botnet forcing consumer TV boxes to relay traffic

Malware Activity
H score76 First: 18.06.2026 20:37 Last: 18.06.2026 20:37 Sources 1

About this happening: Popa is an Android-based botnet that turns consumer TV boxes and related devices into relay infrastructure, maintaining encrypted connectivity and opening tunnels on d...

Latest development: 03.07.2026 12:35

Google disabled NetNut accounts used for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing compromised SDKs while FBI legal actions and domain seizures targeted NetNut infrastructure. The coordinated disruption was described as degrading NetNut’s proxy network and shrinking the pool of devices available to the operator.

NCSC-UK joint advisory on covert botnets and proxy networks

Public Sector Action
H score66 First: 23.04.2026 15:28 Last: 23.04.2026 15:28 Sources 1

About this happening: NCSC-UK and partner agencies issued a joint advisory warning that China-nexus hackers are using hijacked consumer devices as covert proxy networks to hide maliciou...

Timeline

  1. 22.06.2026 09:57 1 articles · 23d ago

    AryStinger spreads from 107.150.106.14 to Realtek RTL819X routers

    Detection Ioc Update

    QiAnXin XLab observed AryStinger spreading from a single source IP, 107.150.106.14, to legacy routers built on Realtek RTL819X chips. The Linux ELF payload exploited CVE-2013-3307 on Linksys models and CVE-2016-5681 on D-Link models to turn the devices into reconnaissance nodes and traffic relays.

    Show sources
  2. 22.06.2026 09:57 2 articles · 23d ago

    QiAnXin XLab discloses AryStinger's router reconnaissance network

    Initial Disclosure

    QiAnXin XLab disclosed AryStinger as a new malware family that turns forgotten home routers into a distributed reconnaissance and proxy network. XLab said it had seen at least 4,300 infected routers and that the total was still rising; the pool was mostly D-Link, with the DIR-850L making up about 75 percent, and XLab also noted a separate QNAP NAS strain.

    Show sources