AryStinger the botnet that turns obsolete routers into proxies for global attacks and DNS surveillance

Author: Published 4 min de lectura 161 reading

The images in this article were generated with artificial intelligence. How we publish

Researchers from the firm Qianxin XLab have identified a new botnet, baptized as AryStinger which has already taken over 4,000 obsolete routers to use them as proxys and remote agents in malicious operations. According to the technical report published by XLab, the infected devices act as "exectors" capable of running distributed network sweeps, tunelization, remote execution of commands and traffic handling DNS, making each router committed to a launch station for subsequent attacks: from mass recognition to silent data theft in transit. More technical details of the finding are available in the analysis of XLab: https: / / blog.xlab.qianxin.com / arystinger-botnet-hijacks-legacy-routers-for-global-attacksen- /.

AryStinger's input vector are ancient vulnerabilities present in unsupported firmware; XLab points to failure exploitation as CVE-2013-3307, CVE-2016-5681 and CVE-2025-11837, and a focus on D-Link DIR-850L and DIR-818LW models, devices that had already been targeted for previous campaigns. D-Link published warnings related to attacks on these models in the past, which highlights the risk of using EoL hardware (end-of-life): https: / / support.

AryStinger the botnet that turns obsolete routers into proxies for global attacks and DNS surveillance
Image generated with IA.

Beyond the scale, what is worrying is the operational architecture: AryStinger distributes recognition tasks among multiple committed routers, which accelerates the mapping of targets and reduces visibility for centralized defenses. XLab also described two families within the same malicious project: a C variant directed mainly at obsolete routers and a Go-oriented variant with expanded capabilities - including source code execution in several languages and use of open source penalizing tools - although still with limited scope compared to the routers variant.

The capabilities observed allow attackers not only to route malicious traffic through other devices, but also handling DNS to kidnap the navigation, and even inspect and copy incoming and outgoing traffic. This transforms an infected router into a persistent surveillance point within a domestic or small office network, with potential impact on authentication, online banking and corporate services accessed from these segments.

For owners and administrators the first lesson is simple and urgent: unsupported hardware is dangerously vulnerable. Replace EoL routers with supported models, apply any available patch or update and follow manufacturer recommendations should be the priority. In addition to updating firmware, there are immediate mitigation measures that reduce the risk of engagement: change default passwords, disable remote management by WAN, close unnecessary ports, disable UPnP and WPS, and segment the network to separate IOT and user devices from sensitive resources.

In advanced organizations and users it is appropriate to add detection controls: monitor unusual DNS patterns and outgoing traffic to unknown servers, search processes that open proxy services in unusual ports, and audit router logs for changes in DNS configuration or NAT rules. Network inspection tools and flow sensors can identify distributed scanning peaks or atypical volumes of DNS queries that indicate malicious use of infrastructure.

AryStinger the botnet that turns obsolete routers into proxies for global attacks and DNS surveillance
Image generated with IA.

Not all technical possibilities are easy to exploit in all environments: XLab points out that the execution of source code in the NAS variant requires runtimes and compilers, which can generate noise and raise alerts. However, this does not reduce the urgency: the combination of large vulnerable surface and the ability to convert devices to proxies makes AryStinger a useful facilitator for attackers who seek to anonymize activity or to pivote towards internal networks.

For those who manage fleets of small devices or networks, the strategy should be double: immediate mitigation to close known vectors and medium-term planning for sanitation and replacement of equipment. Safety documents and good practices for IoT and network devices, such as the OWASP IoT project resources, help prioritize technical controls and replacement processes: https: / / owasp.org / www-project-internet-of-things /. In corporate environments, including specific penetration tests on routers and NAS, as well as distributed attack simulations, will allow to check if the controls deployed today detect or block patterns such as those described by XLab.

Finally, if you suspect that your router has been compromised, restart it to factory values, update firmware with an official image, change credentials and, where possible, replace the equipment with one with current support. If the device belongs to a service provider, contact the technical support immediately. The persistence of botnets like AryStinger recalls that network security begins with the most basic perimeter: the router that many neglect.

Coverage

Related

More news on the same subject.