Thousands of D-Link and QNAP NAS routers compromised by fast-moving AryStinger malware that turns unsecured devices into a malicious proxy botnet


  • QiAnXin
  • So far, 4,300 routers have been infected, mainly in South Korea (48%) and China (32%), with QNAP NAS devices also targeted via CVE‑2025‑11837.
  • Compromised devices enable scanning, tunneling and covert control; researchers advise monitoring logs, binaries in /tmp/bin, and suspicious processes like syswapd0h Or syswapd0w

Cybersecurity researchers QiAnXin XLab are warning of an ongoing campaign to create a distributed reconnaissance and proxy network from users’ routers and NAS devices.

The cam has malware called AryStinger.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top