Particle.news
Download on the App Store

AryStinger Malware Hijacks 4,300+ Legacy Routers to Build Reconnaissance and Proxy Fleet

Security researchers warn the campaign converts end‑of‑life routers and some NAS boxes into covert scanners and relays that can intercept and redirect traffic.

Overview

  • QiAnXin XLab first flagged the activity after seeing a spreading ELF sample in March 2026 and researchers now count at least about 4,300 infected RTL819X‑based routers with the total still rising.
  • The campaign uses two builds: a lightweight C binary for Realtek RTL819X routers and a more capable Go build for QNAP NAS devices that can run attacker-supplied Go, Java, or Python code.
  • Operators exploit old, public CVEs including CVE-2013-3307 and CVE-2016-5681 against routers and CVE-2025-11837 against NAS devices to gain access to unpatched, end‑of‑life hardware.
  • Infected machines act as distributed 'Executors' that perform mass scanning, subdomain enumeration, tunneling and proxying, can tamper with DNS and capture traffic, and use Dropbear on port 2332 and an XOR‑obfuscated Protobuf C2 with the hardcoded key sh_#@!_2024_secret for persistence and control.
  • Researchers urge owners to retire unsupported routers, apply available firmware and configuration hardening, and hunt for published IOCs such as process names syswapd0h/syswapd0w, domains like ajb8.com, and unexpected Dropbear on port 2332 because compromised routers can leak credentials and be used to hide later intrusions.