Home Botnet Hackers Exploit 13-Year-Old Router Flaws to Deploy AryStinger Botnet

Hackers Exploit 13-Year-Old Router Flaws to Deploy AryStinger Botnet

0
AryStinger Botnet Exploits Routers
AryStinger Botnet Exploits Routers

Threat actors are increasingly targeting outdated networking equipment to establish sophisticated reconnaissance networks.

Security researchers recently uncovered an unusual attack campaign that exploits vulnerabilities disclosed over a decade ago to compromise older routers.

Unlike typical botnets designed for distributed denial-of-service attacks or cryptocurrency mining, this newly discovered malware family focuses heavily on intrusion reconnaissance.

Named “AryStinger” by QiAnXin XLab researchers, this botnet turns legacy devices into covert springboards for information gathering, port scanning, and traffic tunneling.

The campaign primarily targets routers equipped with RTL819X series chips, which were mainstream between 2012 and 2015.

Attackers weaponize old vulnerabilities, specifically CVE-2013-3307 and CVE-2016-5681, to infect legacy Linksys and D-Link devices.

Once compromised, each infected device becomes a node within a distributed scanning cluster. Telemetry data indicates that over 4,300 routers worldwide have already been infected.

The highest concentrations of compromised devices are located in South Korea and China. However, significant infections have also appeared in Sweden and Malaysia.

AryStinger Botnet Exploits Routers (Source: qianxin)
AryStinger Botnet Exploits Routers (Source: qianxin)

AryStinger Botnet Exploits Routers

AryStinger operates using two distinct variants tailored to different hardware environments. The first variant is implemented in C and specifically targets older, resource-constrained routers using the RTL819X chips.

This streamlined version focuses on essential tasks like DNS scanning and tunnel establishment. It installs a lightweight SSH server, Dropbear on the device to create a persistent remote management channel.

Despite its simplicity, this version effectively harnesses legacy hardware to perform parallel scanning tasks distributed by the attacker’s command-and-control infrastructure.

AryStinger Botnet Exploits Routers (Source: qianxin)
AryStinger Botnet Exploits Routers (Source: qianxin)

The second variant, known as the Standard version, is written in Go and targets network-attached storage devices by exploiting CVE-2025-11837.

This version is significantly more robust and includes an integrated suite of penetration testing tools, such as Fscan and Ksubdomain.

According to QiAnXin research, the Standard version of AryStinger introduces advanced capabilities that make it a formidable threat for lateral movement.

The central server can issue a variety of specialized commands, including internal network scanning, service identification, and dynamic payload execution.

Notably, the botnet supports running source-level payloads in Go, Java, and Python. This architectural choice allows attackers to bypass the need to compile specific binaries, opting instead to distribute text scripts that execute dynamically on the host device.

By splitting massive scanning tasks into smaller chunks and delegating them to different compromised endpoints, hackers efficiently gather footprinting data.

To protect against this evolving threat, organizations and individuals must proactively manage their network edge devices.

Old routers lacking recent firmware updates are highly susceptible to becoming permanent, invisible listening devices for threat actors.

Discarding obsolete hardware removes a critical entry point that cybercriminals use to hide their true identities and physical locations.

Indicators of Compromise

Indicator TypeValue
C2 Domain / URLhttp://opi7.com
C2 Domain / URLhttp://xook.ajb8.com
C2 Domain / URLhttp://xonice.ahb8.com

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here