All incidents

AryStinger malware infects routers via CVE-2013-3307

malwareclosedJun 22, 2026 — Jun 23, 2026
AryStinger malware hijacks over 4,300 outdated routers in Asia

OVER 4,300 outdated routers have been hijacked by AryStinger malware in Asia, forming a botnet for reconnaissance according to QiAnXin XLab.

The malware exploits CVE-2013-3307 (CVSS 8.3) and CVE-2016-5681, for which a patch is available, to gain control of devices as reported by SecurityOnline.

Infection involves a multi-stage process that creates Executor modules for routers and NAS, enabling port scanning and DNS tampering per Malwarebytes.

Active exploitation was observed between 22 and 23 June 2026, with infections concentrated in South Korea and China according to SecurityAffairs.

Administrators should monitor traffic for unusual spikes, check for unknown outbound connections and review device logs for signs of compromise as advised by the researchers.

Given the age of the hardware, the most effective mitigation is to replace end-of-life devices with supported models and regularly audit inventory for legacy routers as recommended by Malwarebytes.

Intelligence briefing updated Jun 23, 2026

CVE-2013-3307 8.3 CVE-2016-5681
Root sourceblog.xlab.qianxin.com
Timeline Coverage

Swipe to explore timeline