securityonline.info 6/23/2026, 9:29:16 AM · external

AryStinger malware hijacks over 4,300 outdated routers in Asia

AryStinger malware hijacks over 4,300 outdated routers in Asia
Developing story vulnerability 3 articles tracked
AryStinger malware hijacks over 4,300 outdated routers in Asia
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Available

SECURITY researchers at QiAnXin XLab have uncovered AryStinger malware infecting over 4,300 outdated routers worldwide, particularly targeting RTL819X series devices. This malware exploits vulnerabilities such as CVE-2013-3307 and CVE-2016-5681 to create a large botnet for intrusion reconnaissance. The infections, concentrated in South Korea and China, lead to potential threats to privacy and national security.

The infection process involves multiple stages, including establishing persistent management channels and collecting device information to send back to command servers. To counteract these threats, network administrators are advised to monitor for signs of infection and replace legacy hardware.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline