Over 4,300 outdated routers worldwide have been hijacked via decade-old vulnerabilities and repurposed as a distributed reconnaissance network by AryStinger malware. The infected devices—primarily D-Link routers running 2012-2015 era firmware—execute coordinated port scanning and subdomain enumeration tasks in parallel while masking the attacker's location. This infrastructure model mirrors state-sponsored operational relay networks used for pre-intrusion intelligence gathering. The exploitation window between QNAP patch release and active abuse suggests sophisticated operators systematically mapping enterprise networks before strikes, with potential reconnaissance activity dating to 2024.
Read the full article at Security Affairs
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.





