AryStinger is a botnet malware family that compromises legacy edge devices, primarily end-of-life routers and some NAS appliances, to build a distributed reconnaissance and proxy infrastructure. It has been observed infecting thousands of outdated internet-facing devices worldwide, with infections heavily concentrated in older D-Link routers built on Realtek RTL819X chipsets and additional activity against QNAP NAS systems. Rather than focusing primarily on distributed denial-of-service or cryptomining, AryStinger is designed to support pre-intrusion operations by turning compromised devices into remotely managed executors for scanning, service discovery, subdomain enumeration, traffic tunneling, and operator-directed command execution.
The malware has been associated with exploitation of known vulnerabilities in older Linksys and D-Link router models, as well as CVE-2025-11837 affecting QNAP Malware Remover on NAS devices. Two main variants have been reported: a lightweight C-based router variant optimized for constrained hardware, and a more capable Go-based NAS variant. The NAS-oriented build expands functionality with broader reconnaissance and execution features, including the ability to run attacker-supplied code or scripts when the required runtimes are present.
AryStinger communicates with command-and-control infrastructure over HTTP and HTTPS using obfuscated serialized messaging, and it maintains long-term access through persistent remote-access mechanisms on infected devices. Reported capabilities include distributed network scanning, port discovery, service fingerprinting, subdomain enumeration, proxying and traffic relay, tunneling, and remote command execution. The Go-based variant also supports follow-on reconnaissance inside local networks. The operational model resembles router-based proxy and operational relay box infrastructures used to conceal attacker origin and stage later intrusion activity. Public reporting has not attributed AryStinger to a specific threat actor with confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The binary exploited two vulnerabilities from another era: CVE-2013-3307 in Linksys routers and CVE-2016-5681 in D-Link models. | A previously undocumented malware botnet named AryStinger has compromised more than 4,300 outdated routers worldwide, turning them into a distributed reconnaissance and proxy network for stealthy cyber espionage operations.
CVE-2025-11837: A code injection flaw in QNAP's Malware Remover (CVSS 9.8), demonstrated at Pwn2Own Ireland 2025 and patched in November 2025. | A previously undocumented malware botnet named AryStinger has compromised more than 4,300 outdated routers worldwide, turning them into a distributed reconnaissance and proxy network for stealthy cyber espionage operations.
AryStinger exploits decade-old vulnerabilities — CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837 — to infect legacy routers and QNAP NAS devices. | A previously undocumented malware botnet named AryStinger has compromised more than 4,300 outdated routers worldwide, turning them into a distributed reconnaissance and proxy network for stealthy cyber espionage operations.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Default logins invite trouble - switching them strengthens access control.
Default logins invite trouble - switching them strengthens access control.
Persistence is maintained via Dropbear SSH on port 2332 (router variant) or gs-netcat (NAS variant), providing permanent remote access backdoors that survive device reboots.
This newer edition brings extra functions: it scans IPs and DNS entries, runs commands remotely, drops payloads, explores local networks.
Obfuscated communication: AryStinger uses HTTP and HTTPS, with Protocol Buffers and XOR-obfuscated data.
C2 communications use HTTP/HTTPS with Protobuf encoding and XOR obfuscation (gzip added in Go variant) to blend with legitimate web traffic and evade network-based detection.
The report states that attackers used older disclosed vulnerabilities to compromise legacy router devices and turn them into infrastructure for scanning, proxying, tunneling, command execution, and related attacker-directed activity.
This newer edition brings extra functions: it scans IPs and DNS entries, runs commands remotely, drops payloads, explores local networks.
80 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a comparison point for repurposing consumer routers into a proxy network.
Referenced as a comparable router proxy network that similarly repurposes consumer equipment.
Botnet family that enrolls older vulnerable home routers into a distributed reconnaissance and proxy network.
Botnet malware that recruits vulnerable home routers for distributed reconnaissance and proxying.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.