ctipilot.ch

Linksys/D-Link RTL819X command-injection RCE — initial-access vector for the AryStinger botnet

cve · CVE-2013-3307

Coverage timeline
1
first 2026-06-22 → last 2026-06-22
Peak priority
high
1 high
Sources cited
11
3 hosts
Sections touched
1
deep-dive
Co-occurring entities
3
see Related entities below
ATT&CK techniques
12
pinned v19.1 · see below

ATT&CK techniques

12 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1595Active Scanning×1

Adversaries may execute active reconnaissance scans to gather information that can be used during targeting. Active scans are those where the adversary probes victim infrastructure via network traffic, as opposed to other forms of reconnaissance that do not involve direct interaction.

Evidence: 2026-06-22/arystinger-a-reconnaissance-and-proxy-botnet-built-on-end-of · ATT&CK page ↗

Initial Access TA0001

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-06-22/arystinger-a-reconnaissance-and-proxy-botnet-built-on-end-of · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-06-22/arystinger-a-reconnaissance-and-proxy-botnet-built-on-end-of · ATT&CK page ↗

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-06-22/arystinger-a-reconnaissance-and-proxy-botnet-built-on-end-of · ATT&CK page ↗

T1059.006Command and Scripting Interpreter: Python×1

Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.

Evidence: 2026-06-22/arystinger-a-reconnaissance-and-proxy-botnet-built-on-end-of · ATT&CK page ↗

Persistence TA0003

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-06-22/arystinger-a-reconnaissance-and-proxy-botnet-built-on-end-of · ATT&CK page ↗

Stealth TA0005

T1036Masquerading×1

Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names.

Evidence: 2026-06-22/arystinger-a-reconnaissance-and-proxy-botnet-built-on-end-of · ATT&CK page ↗

Defense Impairment TA0112

T1685Disable or Modify Tools×1

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Evidence: 2026-06-22/arystinger-a-reconnaissance-and-proxy-botnet-built-on-end-of · ATT&CK page ↗

T1686Disable or Modify System Firewall×1

Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action. Once an adversary has gathered sufficient privileges, they can tamper with firewall services, policies, or rule sets to remove restrictions on inbound or outbound traffic. For example, this may include turning off firewall profiles, altering existing rules to permit previously blocked ports or protocols, or adding new rules that create covert communication paths (e.g., adding a new firewall rule for a well-known protocol (such as RDP) using a non-traditional and potentially less securitized port.

Evidence: 2026-06-22/arystinger-a-reconnaissance-and-proxy-botnet-built-on-end-of · ATT&CK page ↗

Discovery TA0007

T1046Network Service Discovery×1

Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.

Evidence: 2026-06-22/arystinger-a-reconnaissance-and-proxy-botnet-built-on-end-of · ATT&CK page ↗

Command and Control TA0011

T1090Proxy×1

Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.

Evidence: 2026-06-22/arystinger-a-reconnaissance-and-proxy-botnet-built-on-end-of · ATT&CK page ↗

T1090.002Proxy: External Proxy×1

Adversaries may use an external proxy to act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths to avoid suspicion.

Evidence: 2026-06-22/arystinger-a-reconnaissance-and-proxy-botnet-built-on-end-of · ATT&CK page ↗

T1572Protocol Tunneling×1

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

Evidence: 2026-06-22/arystinger-a-reconnaissance-and-proxy-botnet-built-on-end-of · ATT&CK page ↗

Story timeline

  1. 2026-06-22AryStinger: a reconnaissance-and-proxy botnet built on end-of-life D-Link routers and QNAP NAS
    deep-dive

Where this entity is cited

  • deep-dive1

Source distribution

  • attack.mitre.org9 (82%)
  • bleepingcomputer.com1 (9%)
  • blog.xlab.qianxin.com1 (9%)

Related entities

Entries about Linksys/D-Link RTL819X command-injection RCE — initial-access vector for the AryStinger botnet (1)

2026-06-22 · view entry permalink →

HIGHCVE-2013-3307 +2exploited

AryStinger: a reconnaissance-and-proxy botnet built on end-of-life D-Link routers and QNAP NAS

QiAnXin XLab disclosed AryStinger, a previously-undocumented botnet its telemetry first observed on 2026-03-12, with English-language follow-up reporting on 2026-06-21 (QiAnXin XLab, 2026-06-17; BleepingComputer, 2026-06-21). Unlike the DDoS- and cryptomining-oriented router botnets that dominate this device class, AryStinger's design centre is pre-intrusion reconnaissance and traffic laundering: infected nodes are enrolled as "Executors" and handed distributed scanning and DNS-brute-force tasks by a C2 controller, and they relay the operator's attack traffic so its true origin is hidden. XLab counts at least 4,300 infected nodes and rising, distributed South Korea 48.5%, China 31.8%, Sweden 6.4%, Malaysia 3.5%, Singapore 2.5%; detection rate on public multi-engine scanning was zero at disclosure.

Initial access — three public CVEs across two device classes. The router variant spreads through CVE-2013-3307 (command injection in Linksys/D-Link models built on the Realtek RTL819X SoC family) and CVE-2016-5681 (a stack-based buffer overflow in the D-Link DIR-850L HTTP service) — both unauthenticated RCE on devices manufactured 2012–2015. From 2026-04-26 a second, NAS-targeting variant began exploiting CVE-2025-11837, a code-injection flaw in QNAP's Malware Remover utility (fixed in build 6.6.8.20251023; QNAP's advisory scopes the affected product to the 6.6.x line — update to the latest build). Mapped to T1190 Exploit Public-Facing Application (T1190). The most infected models — D-Link DIR-850L (75% of nodes) and DIR-818LW (13%) — are end-of-life with no firmware fix (D-Link support bulletin SAP10503), so for the router population there is no patch and replacement is the only remediation.

Post-exploitation and persistence. After exploitation a downloader pulls the current payload from C2, the bot authenticates with a unique Executor ID, and a Dropbear SSH server is deployed on a fixed non-standard port with an iptables rule added to allow inbound C2 traffic — establishing persistent, system-level remote access (QiAnXin XLab, 2026-06-17). This combines T1133 External Remote Services (T1133) for the SSH backdoor with T1562.004 Impair Defenses: Disable or Modify System Firewall (T1562.004) for the firewall change. The router binary masquerades under a system-daemon-like process name (T1036 Masquerading, T1036).

Two malware variants, different capability tiers. The constrained RTL819X C variant carries massdns-style distributed DNS reconnaissance and a NAT-traversal tunnelling module (T1572 Protocol Tunneling, T1572; T1090.002 external proxy, T1090.002). The Go "Standard" variant for more-capable hosts (NAS) bundles off-the-shelf offensive tooling — fscan, ksubdomain, httpx, tlsx — for network-service discovery and subdomain enumeration (T1046 Network Service Discovery, T1046; T1595 Active Scanning, T1595), plus remote command execution and source-level payload execution in Go/Java/Python. C2 is HTTP/HTTPS with Protobuf message bodies under XOR obfuscation; a hardcoded key string embeds a 2024 marker, suggesting the operation predates the 2026 first-sighting.

Why this matters to a Swiss/EU public-sector SOC. The direct exposure is indirect but real: EoL D-Link SOHO routers persist in branch offices, municipal sites, and home-office setups, and QNAP NAS appliances are widely used as departmental file shares — both populations sit on the audience's attack surface, and Sweden's 6.4% share shows European devices are already being conscripted. A node's job is to scan and proxy, so a compromised device inside or adjacent to an organisation's network becomes a launch point for credential brute-forcing and lateral reconnaissance that looks like it originates from trusted infrastructure.

Hunt and detection concepts (no IOCs). On Linux/MIPS network appliances, hunt for an unexpected Dropbear (or any) SSH daemon listening on a non-standard port and for iptables rules added outside change management. On QNAP and other Linux NAS, alert on curl/python (or other interpreters) spawned from the security-utility process tree (T1059.006, T1059.006) and on file writes into /tmp/bin/ by a service account that should not be writing executables. Network-side, watch for bursts of outbound DNS queries consistent with mass subdomain brute-forcing from edge/IoT VLAN segments, and for long-lived outbound SSH from device-management ranges. Inventory edge devices for the affected D-Link models and for QNAP Malware Remover build numbers.

Hardening. Replace EoL D-Link DIR-850L / DIR-818LW (and same-era RTL819X models) — there is no firmware path. Patch QNAP Malware Remover to 6.6.8.20251023 or later. Restrict inbound SSH on management VLANs to known jump hosts, and apply egress filtering so SOHO/IoT segments cannot freely initiate outbound SSH or high-volume DNS. Attribution: XLab claims none; the brief reports the activity as XLab characterises it, not as a named actor.

QiAnXin XLab disclosed AryStinger, a previously-undocumented botnet its telemetry first observed on 2026-03-12, with English-language follow-up reporting on 2026-06-21 (QiAnXin XLab, 2026-06-17; BleepingComputer, 2026-06-21).

ctipilot v2 brief (migrated)
vulnerability22 Jun 04:52Zmulti-sourceOpen finding ↗