
QiAnXin XLab discovered AryStinger malware infecting at least 4,300 legacy Realtek RTL819X routers, mostly D-Link DIR-850L models. The malware builds a reconnaissance proxy network for pre-breach scanning, fingerprinting, and traffic tunneling. A second strain targets QNAP NAS devices via CVE-2025-11837.
Tap to vote and see what everyone thinks.
Summary by ByteBrief
DragonForce Abuses Microsoft Teams Relays for C2 Traffic