AryStinger Botnet Infects Thousands of D-Link Routers Globally

A newly discovered botnet targets end-of-life D-Link routers, turning them into proxies for cyberattacks worldwide.

By Central
Over 4,000 D-Link routers compromised by the AryStinger botnet, with infections concentrated in South Korea and China.
Highlights
  • AryStinger infects 4,000+ end-of-life D-Link routers, using them as remote proxies for scanning and tunneling.
  • Nearly half of all infections are in South Korea, followed by China at 31.8%.
  • Users should replace unsupported routers and disable remote management to prevent exploitation.

A newly identified malware botnet designated AryStinger has compromised over 4,000 end-of-life routers worldwide, transforming them into remotely controlled proxies for scanning, tunneling, and command execution. Researchers at Qianxin’s XLab threat intelligence team discovered the botnet targeting D-Link DIR-850L and DIR-818LW devices through a trio of known vulnerabilities, raising serious concerns about the lingering risks posed by unsupported networking hardware.

How the AryStinger Botnet Operates

AryStinger converts infected routers into what XLab calls “executors,” allowing attackers to distribute large-scale scanning tasks across multiple compromised devices for parallel execution. This distributed architecture enables efficient network footprinting, with the botnet capable of performing IP and DNS scanning, traffic proxying, tunneling, and remote command execution. The malware also possesses the ability to tamper with DNS settings, hijack browsing sessions, and silently monitor all inbound and outbound network traffic passing through the router.

XLab researchers identified two distinct variants of the malware. The primary variant is a C-based build targeting legacy routers, while a more advanced Go-based variant focuses on network-attached storage (NAS) systems. The NAS variant integrates open-source penetration testing tools, supporting not only Shell commands but also execution of Go, Java, and Python source code. This flexibility, however, comes with operational limitations: source code compilation requires language runtimes on the host, and the process introduces noise that can undermine stealth.

Exploited Vulnerabilities and Affected Devices

The botnet exploits three specific flaws: CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837. These vulnerabilities affect primarily the D-Link DIR-850L and D-Link DIR-818LW router models, both of which are end-of-life products that no longer receive security updates from the manufacturer. The same device models were previously targeted by the AVrecon malware botnet, which was disrupted in 2023 by Lumen Technologies.

XLab’s telemetry data reveals that nearly half of all AryStinger infections are concentrated in South Korea, accounting for 48.5 percent of compromised devices. China follows at 31.8 percent, with Sweden at 6.4 percent, Malaysia at 3.5 percent, and Singapore at 2.5 percent. The remaining infections are distributed across other regions globally.

What Is the AryStinger Botnet?

AryStinger is a malware botnet that infects outdated routers and converts them into remote proxies for malicious cyber operations. It uses a distributed executor model to perform scanning, tunneling, and command execution on behalf of attackers. The botnet primarily targets end-of-life D-Link router models and exploits known vulnerabilities that have never been patched by the manufacturer.

Potential for DNS-Based Attacks

The researchers noted that AryStinger’s distributed DNS-scanning infrastructure could theoretically be repurposed to generate high volumes of DNS queries against resolvers, effectively weaponizing the botnet for amplification or reflection attacks. XLab stated that they have not yet observed such activity, but the architectural capability exists within the malware’s design. The researchers did not attribute AryStinger to any known threat actor group, noting that “many mysteries surrounding AryStinger remain to be solved.”

What Affected Users Should Do Now

Owners of D-Link DIR-850L and DIR-818LW routers, or any other end-of-life networking hardware, should take immediate action. The most effective step is to replace the device with a new, actively supported router that receives regular firmware security updates. For the current device, users should apply any available firmware updates from the manufacturer, change the default administrator account password to a strong, unique credential, and disable remote management panels if they are not strictly necessary for legitimate administration purposes.

Affected users should also monitor network traffic for unusual DNS queries or unexpected outbound connections. Deploying a reputable endpoint protection solution with behavioral analysis capabilities can help detect malware activity on devices connected to compromised routers. For organizations, segmenting legacy or IoT devices onto separate network VLANs can limit the blast radius should a router become infected.

This incident underscores a critical cybersecurity reality: end-of-life hardware is a persistent and exploitable attack surface. Manufacturers stop issuing patches, but attackers continue to reverse-engineer and weaponize the vulnerabilities that remain unaddressed. Replacing unsupported devices is not a convenience — it is a necessary security measure.

Share This Article