AryStinger (Ary-Attack) Botnet Compromises 4,000+ Legacy D-Link/RTL819X Routers and NAS for Global Attack Proxy Infrastructure (CVE-2013-3307, CVE-2016-5681, CVE-2025-11837) — Threadlinqs Intelligence
As of 2026-06-21, AryStinger (Ary-Attack) Botnet Compromises 4,000+ Legacy D-Link/RTL819X Routers and NAS for Global Attack Proxy Infrastructure (CVE-2013-3307, CVE-2016-5681, CVE-2025-11837) is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 32 indicators of compromise.
Threat ID: TL-2026-0894 · Severity: HIGH · CVSS: 9.8 · Status: ACTIVE · Category: MALWARE
AryStinger is an actively spreading multi-platform botnet, internally named 'Ary-Attack', that has compromised more than 4,300 legacy RTL819X-based D-Link routers (predominantly DIR-850L and
AryStinger is a botnet-as-attack-infrastructure operation tracked by Qianxin's XLab threat intelligence team, with an internal project name of 'Ary-Attack' derived from Go source-path hints in the malware. The operation builds a globally distributed cluster of compromised edge devices used as proxies and reconnaissance executors for downstream intrusion activity.
The campaign comprises two homologous but distinct malware families. The first is a C-implemented, MIPS (RTL819X) ELF binary ('RTL819X version') that targets outdated Realtek RTL819X-based SOHO routers — principally legacy D-Link models. XLab captured 32 versions of this variant; it is deployed as 'syswapd0' into /tmp/bin/ and is delivered via shell scripts downloaded from the operator's distribution servers after exploitation of CVE-2013-3307 and CVE-2016-5681. The second is a Go-implemented x86-64 ELF binary ('Standard version', UPX-packed, deployed as 'syswapd0-linux-amd64') that targets NAS devices via CVE-2025-11837 and carries richer capabilities: it captured 22 versions and supports dynamic interpreter-based execution of Shell, Go, Java and Python payloads, intranet mapping, and integrated offensive tooling (fscan, ksubdomain, httpx, tlsx).
Once installed, an executor registers with the C2 by collecting host fingerprint data (MAC address, device name, public/internal IP, OS version, CPU architecture, timestamp) and POSTing it to an /auth endpoint, which returns a numeric Executor ID. The bot then maintains a heartbeat against /heartbeat and /config for configuration updates, and pulls tasks from /cmd using an 'X-Executor-ID' header. The Standard version implements discrete task types — ScriptWork (shell/code execution), DnsWork, HttpAliveWork, HttpScanWork, DomainScanWork and IPScanWork — coordinating large-scale distributed subdomain enumeration, port/service scanning and HTTP probing across the bot fleet. Communications are obfuscated with XOR encryption using the hardcoded key 'sh_#@!_2024_secret', and the Standard version additionally uses Protobuf with Gzip compression.
Persistence and remote access differ by variant. The RTL819X variant deploys a Dropbear SSH backdoor on TCP port 2332 with supporting iptables rules; the Standard version deploys gs-netcat for remote shell and a separate tunneling component (nat_tunnel-linux-x86_64) delivered by a Python stager for proxying/tunneling. The malware also advertises a DNS-hijacking capability to tamper with victim DNS settings and redirect browsing. Detection rates against mainstream antivirus were near zero at time of reporting, and the nat_tunnel component is suspected of being partly AI-generated. Affected devices are concentrated in South Korea (48.45%) and China (31.82%), with additional infections in Sweden, Malaysia and Singapore. The botnet remains active and unattributed.
Weaknesses (CWE)
CWE-121, CWE-78, CWE-119, CWE-77
Target sectors: telecommunications, consumer, small-business, technology
Target regions: South Korea, China, Sweden, Malaysia, Singapore, Asia, Europe
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 32 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, CVE-2013-3307, CVE-2016-5681, CVE-2025-11837, T1595, T1595, T1590, T1596, T1584, T1587, T1190, T1059, T1059, T1133