AryStinger is a malware botnet that compromises legacy edge devices, primarily end-of-life routers and some NAS appliances, and repurposes them as a distributed reconnaissance and proxy infrastructure. It has been observed targeting older Realtek RTL819X-based routers, especially certain D-Link models, and a separate Go-based variant has targeted QNAP NAS devices via CVE-2025-11837. Initial access has also been linked to exploitation of CVE-2013-3307 and CVE-2016-5681 on vulnerable router platforms.
Unlike many IoT botnets that focus on distributed denial-of-service or cryptomining, AryStinger is oriented toward pre-intrusion operations and covert infrastructure building. Infected devices act as remotely tasked executors that perform internet and intranet reconnaissance, including port scanning, service identification, DNS or subdomain enumeration, and broader fingerprinting of exposed services. The botnet also supports traffic tunneling and proxying, allowing operators to relay malicious communications through compromised residential or small-office devices and obscure their true origin during follow-on operations.
AryStinger has been documented in at least two main forms: a lightweight C-based router variant optimized for constrained hardware, and a more capable Go-based NAS variant. The NAS-focused build expands functionality with remote command execution and the ability to run attacker-supplied code, including shell commands and source code in multiple languages when the required runtimes are present. The Go variant has also been associated with integrated reconnaissance tooling for broader network discovery and service analysis.
The malware maintains long-term access through persistent backdoor mechanisms on compromised devices. Communications with command-and-control infrastructure use HTTP or HTTPS with obfuscation and structured serialization, and the campaign has shown iterative development over multiple versions. Observed infections have been concentrated in Asia, particularly South Korea and China, with additional global spread. Attribution remains unknown. AryStinger’s operational pattern aligns with the use of compromised edge devices as operational relay and reconnaissance nodes to support later intrusion activity, espionage-oriented staging, or other stealthy attack campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The binary exploited two vulnerabilities from another era: CVE-2013-3307 in Linksys routers and CVE-2016-5681 in D-Link models. | A previously undocumented malware botnet named AryStinger has compromised more than 4,300 outdated routers worldwide, turning them into a distributed reconnaissance and proxy network for stealthy cyber espionage operations.
CVE-2025-11837: A code injection flaw in QNAP's Malware Remover (CVSS 9.8), demonstrated at Pwn2Own Ireland 2025 and patched in November 2025. | A previously undocumented malware botnet named AryStinger has compromised more than 4,300 outdated routers worldwide, turning them into a distributed reconnaissance and proxy network for stealthy cyber espionage operations.
AryStinger exploits decade-old vulnerabilities — CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837 — to infect legacy routers and QNAP NAS devices. | A previously undocumented malware botnet named AryStinger has compromised more than 4,300 outdated routers worldwide, turning them into a distributed reconnaissance and proxy network for stealthy cyber espionage operations.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Default logins invite trouble - switching them strengthens access control.
Default logins invite trouble - switching them strengthens access control.
Persistence is maintained via Dropbear SSH on port 2332 (router variant) or gs-netcat (NAS variant), providing permanent remote access backdoors that survive device reboots.
This newer edition brings extra functions: it scans IPs and DNS entries, runs commands remotely, drops payloads, explores local networks.
Obfuscated communication: AryStinger uses HTTP and HTTPS, with Protocol Buffers and XOR-obfuscated data.
C2 communications use HTTP/HTTPS with Protobuf encoding and XOR obfuscation (gzip added in Go variant) to blend with legitimate web traffic and evade network-based detection.
The report states that attackers used older disclosed vulnerabilities to compromise legacy router devices and turn them into infrastructure for scanning, proxying, tunneling, command execution, and related attacker-directed activity.
This newer edition brings extra functions: it scans IPs and DNS entries, runs commands remotely, drops payloads, explores local networks.
80 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet malware that recruits vulnerable home routers for distributed reconnaissance and proxying.
Mentioned only as another recently identified botnet targeting exposed devices for DDoS and reconnaissance.
Another botnet mentioned in passing as related background on recent botnet activity.
AryStinger is a malware family targeting routers and NAS devices, used to build a covert proxy and reconnaissance infrastructure. It registers infected devices with C2, distributes scanning tasks, supports port scanning, service identification, subdomain enumeration, traffic tunneling, intranet scanning, script execution, and establishes persistent remote access via dropbear or gs-netcat.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.