June 25, 2026
- AryStinger, a previously undocumented Linux botnet, hijacks EoL routers and QNAP NAS as a covert reconnaissance-and-proxy network rather than for DDoS/mining. It uses an Executor/Controller model, n-day CVEs (CVE-2013-3307, CVE-2016-5681, CVE-2025-11837), Protobuf+XOR C2, and Dropbear/gs-netcat persistence; 4,300+ routers confirmed (mostly South Korea and China, ~75% D-Link DIR-850L), initial samples at 0/VirusTotal. XLab via FalconFeeds · Threat Intelligence