Thousands of D-Link and QNAP NAS routers compromised by fast-moving AryStinger malware that turns unsecured devices into malicious proxy botnet



  • QiAnXin XLab discovered “AryStinger”, a malware that exploits old D-Link/Linksys router flaws (CVE‑2013‑3307, CVE‑2016‑5681) to build a proxy/reconnaissance network
  • So far, 4,300 infected routers, mainly in South Korea (48%) and China (32%), and QNAP NAS devices were also attacked via CVE-2025-11837.
  • Compromised devices enable scanning, tunneling, and covert control; Researchers recommend monitoring logs, binaries in /tmp/bin, and suspicious processes like syswapd0h either syswapd0w

Cybersecurity researchers QiAnXin XLab warn of an ongoing campaign to create a distributed reconnaissance and proxy network out of people’s routers and NAS devices.

The campaign targets outdated and unsupported routers (mainly D-Link and Linksys), powered by Realtek’s RTL819X chips, which were a popular choice between 2012 and 2015. Attackers are exploiting two (old) vulnerabilities, CVE-2013-3307 in Linksys models and CVE-2016-5681 in D-Link models, to infect the devices with a previously undetected piece of malware called AryStinger.

Leave a Comment

Your email address will not be published. Required fields are marked *