Free delivery

GGuestNot signed in
You're not signed in
LoginCreate account

6/29/2026 • Security

AryStinger and the Danger of Forgotten Gear for SMBs

A fast-spreading malware family called AryStinger is hijacking old, unpatched routers and NAS devices. Here's why this is really a forgotten-gear story for Australian small businesses — and what to do about it.

A new piece of malware, an old, familiar problem

Security researchers at QiAnXin's XLab recently uncovered a fast-spreading malware family they've named AryStinger. At the time of their report it had hijacked roughly 4,300 or more devices — and the number was still climbing.

What makes AryStinger worth a calm read (rather than a panic) is what it goes after. It mainly targets old, unsupported home and small-office routers — largely D-Link and Linksys models built around 2012–2015 on Realtek RTL819X chips — by exploiting vulnerabilities that have been public for years. We're talking about flaws like CVE-2013-3307 and CVE-2016-5681: holes that were documented and fixable a long time ago, but never patched on the devices still running today.

It also targets QNAP NAS devices through a flaw tracked as CVE-2025-11837, which was found at the Pwn2Own contest and patched by QNAP in November 2025. That's an important detail: patched NAS are protected. It's the unpatched and older devices that remain at risk.

This isn't a botnet that shouts — it's one that listens

Most botnets we hear about exist to launch DDoS attacks. AryStinger is different. It turns infected devices into a reconnaissance and proxy network rather than a DDoS cannon.

Once a device is compromised, it:

  • Scans the internet and fingerprints services
  • Tunnels traffic and runs commands for the operator
  • Installs a Dropbear SSH backdoor for persistent access
  • Rewrites the device's DNS settings
  • Can intercept the traffic passing through it

Infections currently concentrate in South Korea and China. But the underlying lesson applies everywhere — including here in Australia.

The real story: forgotten gear, not a single vendor

Here's the key point we want Australian business owners to take away: this isn't really a D-Link or QNAP story. It's a forgotten-gear story.

Botnets like AryStinger feed on devices that are end-of-life, unpatched, and exposed to the internet. The brand on the box matters far less than whether the device still receives security updates and whether it's reachable from the open internet.

And plenty of Australian small businesses are quietly running exactly this kind of kit:

  • A cheap consumer router that hasn't had a firmware update in years
  • A NAS sitting in the corner, reachable from the internet so staff can grab files from home

None of that is unusual. It's how a lot of small offices grew organically. But it's precisely the soft target this malware is built to find.

Let's be fair while we're at it. QNAP patched the flaw and makes good products. D-Link and Linksys consumer gear is perfectly fine for what it is — home and very light use. The problem isn't the manufacturer. The problem is running unsupported, unpatched devices in a business and exposing them to the internet.

Why a hijacked router or NAS hurts you — even if it's 'just a proxy'

It's tempting to think, "So what if my old router becomes a proxy? I'm not the target." In business terms, that's a costly assumption.

  • Your hardware is used to commit crime. Infected devices scan the internet and proxy traffic for the operator. That activity comes from your IP address — which can get your business blacklisted, breaking email delivery and access to legitimate services.
  • Your DNS can be rewritten. AryStinger changes DNS settings. That means staff trying to reach a real banking, payroll or supplier site can be quietly redirected to a fake or phishing version without anyone noticing the difference.
  • Your traffic can be intercepted. Because the device sits in the path of your data, credentials and sensitive information passing through it can be captured.
  • A NAS often holds your crown jewels. Customer records, financials, contracts, backups. A compromised NAS is not a minor inconvenience — it's potentially a data breach with reporting obligations attached.

No single box is a silver bullet, and no vendor is immune. The point is good hygiene plus supported gear — not chasing a magic device.

What Australian SMBs should do now

Here's a clear, practical checklist. Work through it in order.

  1. Inventory everything. List every router, modem, NAS and IoT device on your network. For each, note its age and whether it still receives firmware updates. You can't protect what you don't know you have.
  2. Retire or replace anything end-of-life. If a device no longer gets patches, it's a liability — full stop. Replace it with supported, business-grade gear. Cloud-managed kit that updates itself automatically is the strongest answer here, because it removes the human step that so often gets forgotten.
  3. Patch everything now — especially your NAS. Apply the QNAP fix for CVE-2025-11837 and keep NAS firmware current going forward. Same hygiene lesson we covered in our FortiBleed write-up: unpatched edge devices are how attackers get in.
  4. Never expose a NAS or admin interface to the internet. Don't port-forward your NAS or a device's management page. Put the NAS behind your firewall and reach it remotely over VPN.
  5. Change default credentials and turn on MFA. Default usernames and passwords are the first thing automated attacks try. Multi-factor authentication stops a stolen password from becoming a full breach.
  6. Watch for warning signs. Be alert to DNS settings you didn't change, unexplained slow internet, unknown SSH access, or odd outbound traffic. These are the fingerprints of exactly this kind of infection.

Where supported, cloud-managed gear fits in

This is the practical reason we keep recommending supported, auto-updating, cloud-managed equipment to our customers — not as a sales pitch, but because it directly addresses the gap AryStinger exploits.

An unpatched edge device becomes a genuine liability the moment it hits end-of-support, which is why we wrote our MX64 End-of-Support planning post — the lesson there is to plan the replacement before the gap opens, not after. A cloud-managed firewall keeps having security updates pushed to it automatically, so you're not relying on someone remembering to log in and patch. And good threat detection helps you notice when something is wrong, rather than finding out months later when your IP is blacklisted.

For most Australian small and medium businesses, a cloud-managed security appliance is the right edge device. From our catalogue, common fits are:

All of them are supported, centrally managed and kept current automatically. Happy to supply other manufacturers too — the principle (supported, patched, not exposed) matters more than the badge.

The honest takeaway

AryStinger isn't a reason to panic. It's a reason to do a tidy-up. The devices most at risk are the ones nobody thinks about — the old router under the desk, the NAS reachable from the internet, the box that hasn't had an update since it was unboxed. Replace what's past its supported life, patch what's current, keep management interfaces off the internet, and you've removed yourself from the target list entirely.

References

Get a check-up from TYO Store

Not sure how old your gear is, or whether it's still getting updates? TYO Store can audit your ageing and at-risk equipment — routers, NAS, the lot — and recommend the right supported replacements, whether that's Cisco Meraki or another manufacturer that fits your needs and budget. Get in touch and we'll help you turn forgotten gear into a network you can stop worrying about.

Contact Us

Email: [email protected]

Phone: 1300 989 334

About

Your one-stop technology hub for all your networking, security, and IT needs. From cutting-edge networking solutions to robust security products, we provide everything your business requires to stay connected, secure, and efficient. Whether you're looking for advanced hardware, software, or services, we offer reliable, innovative technology tailored to help you build and protect your digital infrastructure.

Copyright © 2026 TYONLINE TECHNOLOGY PTY. LTD. All Rights Reserved.