
OVER 4,300 outdated routers have been hijacked by AryStinger malware in Asia, forming a botnet for reconnaissance according to QiAnXin XLab.
The malware exploits CVE-2013-3307 (CVSS 8.3) and CVE-2016-5681, for which a patch is available, to gain control of devices as reported by SecurityOnline.
Infection involves a multi-stage process that creates Executor modules for routers and NAS, enabling port scanning and DNS tampering per Malwarebytes.
Active exploitation was observed between 22 and 23 June 2026, with infections concentrated in South Korea and China according to SecurityAffairs.
Administrators should monitor traffic for unusual spikes, check for unknown outbound connections and review device logs for signs of compromise as advised by the researchers.
Given the age of the hardware, the most effective mitigation is to replace end-of-life devices with supported models and regularly audit inventory for legacy routers as recommended by Malwarebytes.