Kimwolf v7 Android Botnet Uses HTTP/2 to Evade DDoS Detection
Cybersecurity researchers have uncovered a new version of the Kimwolf/AISURU Android and IoT botnet, tracked as Kimwolf v7, which introduces significant enhancements…
Cybersecurity researchers have uncovered a new version of the Kimwolf/AISURU Android and IoT botnet, tracked as Kimwolf v7, which introduces significant enhancements…
Cybersecurity researchers at Palo Alto Networks Unit 42 have disclosed a previously unreported IoT botnet framework named TuxBot v3 Evolution, which shows…
Realtek is a Taiwanese semiconductor company that produces the RTL819X chipset used in legacy routers (circa 2012-2015). These chips are targeted by…
D-Link is a Taiwanese networking equipment manufacturer. Its DIR-850L router model accounts for about 75% of AryStinger infections, exploiting CVE-2016-5681. The company…
QNAP is a Taiwanese manufacturer of network-attached storage (NAS) devices. A second strain of AryStinger exploits CVE-2025-11837 in QNAP's Malware Remover application…
The D-Link DIR-850L is a legacy router model that accounts for about 75% of AryStinger infections. It is vulnerable to CVE-2016-5681 and…
QNAP Malware Remover is a security application for QNAP NAS devices. It contains a code injection vulnerability (CVE-2025-11837) exploited by AryStinger to…
gs-netcat is a networking tool used by AryStinger for persistence on infected QNAP NAS devices, providing remote access and tunneling capabilities.
ksubdomain is a subdomain enumeration tool used by the Go-based build of AryStinger on QNAP NAS devices to discover subdomains during reconnaissance.
httpx is an HTTP probing tool used by the Go-based build of AryStinger on QNAP NAS devices to fingerprint web services during…