{"id":57541,"date":"2026-06-21T17:52:28","date_gmt":"2026-06-21T21:52:28","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=57541"},"modified":"2026-06-21T17:52:28","modified_gmt":"2026-06-21T21:52:28","slug":"arystringer-botnet-dlink-routers","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/arystringer-botnet-dlink-routers\/","title":{"rendered":"AryStinger Botnet Infects Thousands of D-Link Routers Globally"},"content":{"rendered":"<p>A newly identified malware botnet designated AryStinger has compromised over 4,000 end-of-life routers worldwide, transforming them into remotely controlled proxies for scanning, tunneling, and command execution. Researchers at Qianxin&#8217;s XLab threat intelligence team discovered the botnet targeting <a href=\"https:\/\/support.dlink.com\/productinfo.aspx?m=DIR-850L\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">D-Link DIR-850L<\/a> and DIR-818LW devices through a trio of known vulnerabilities, raising serious concerns about the lingering risks posed by unsupported networking hardware.<\/p>\n<h2>How the AryStinger Botnet Operates<\/h2>\n<p>AryStinger converts infected routers into what XLab calls &#8220;executors,&#8221; allowing attackers to distribute large-scale scanning tasks across multiple compromised devices for parallel execution. This distributed architecture enables efficient network footprinting, with the botnet capable of performing IP and DNS scanning, traffic proxying, tunneling, and remote command execution. The malware also possesses the ability to tamper with DNS settings, hijack browsing sessions, and silently monitor all inbound and outbound network traffic passing through the router.<\/p>\n<p>XLab researchers identified two distinct variants of the malware. The primary variant is a C-based build targeting legacy routers, while a more advanced Go-based variant focuses on network-attached storage (NAS) systems. The NAS variant integrates open-source penetration testing tools, supporting not only Shell commands but also execution of Go, Java, and Python source code. This flexibility, however, comes with operational limitations: source code compilation requires language runtimes on the host, and the process introduces noise that can undermine stealth.<\/p>\n<h2>Exploited Vulnerabilities and Affected Devices<\/h2>\n<p>The botnet exploits three specific flaws: CVE-2013-3307, CVE-2016-5681, and <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-11837\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">CVE-2025-11837<\/a>. These vulnerabilities affect primarily the D-Link DIR-850L and D-Link DIR-818LW router models, both of which are end-of-life products that no longer receive security updates from the manufacturer. The same device models were previously targeted by the AVrecon malware botnet, which was disrupted in 2023 by Lumen Technologies.<\/p>\n<p>XLab&#8217;s telemetry data reveals that nearly half of all AryStinger infections are concentrated in <a href=\"https:\/\/overcentral.com\/en\/brain-implant-power-user-south-korea-ai\/\" title=\"First brain implant power user emerges as South Korea embraces AI\" data-iacss-internal=\"1\">South Korea<\/a>, accounting for 48.5 percent of compromised devices. <a href=\"https:\/\/overcentral.com\/en\/tesla-fsd-fraud-lawsuit-china\/\" title=\"Tesla Faces First FSD Fraud Lawsuit Hearing in China\" data-iacss-internal=\"1\">China<\/a> follows at 31.8 percent, with Sweden at 6.4 percent, Malaysia at 3.5 percent, and Singapore at 2.5 percent. The remaining infections are distributed across other regions globally.<\/p>\n<h2>What Is the AryStinger Botnet?<\/h2>\n<p>AryStinger is a malware botnet that infects outdated routers and converts them into remote proxies for malicious cyber operations. It uses a distributed executor model to perform scanning, tunneling, and command execution on behalf of attackers. The botnet primarily targets end-of-life D-Link router models and exploits known vulnerabilities that have never been patched by the manufacturer.<\/p>\n<h2>Potential for DNS-Based Attacks<\/h2>\n<p>The researchers noted that AryStinger&#8217;s distributed DNS-scanning infrastructure could theoretically be repurposed to generate high volumes of DNS queries against resolvers, effectively weaponizing the botnet for amplification or reflection attacks. XLab stated that they have not yet observed such activity, but the architectural capability exists within the malware&#8217;s design. The researchers did not attribute AryStinger to any known <a href=\"https:\/\/overcentral.com\/en\/darkweb-threat-actor-czech-republic-data-breach\/\" title=\"DarkWeb Threat Actor Exposes Czech Republic Data Breach\" data-iacss-internal=\"1\">threat actor<\/a> group, noting that &#8220;many mysteries surrounding AryStinger remain to be solved.&#8221;<\/p>\n<h2>What Affected Users Should Do Now<\/h2>\n<p>Owners of D-Link DIR-850L and DIR-818LW routers, or any other end-of-life networking hardware, should take immediate action. The most effective step is to replace the device with a new, actively supported router that receives regular firmware security updates. For the current device, users should apply any available firmware updates from the manufacturer, change the default administrator account password to a strong, unique credential, and disable remote management panels if they are not strictly necessary for legitimate administration purposes.<\/p>\n<p>Affected users should also monitor network traffic for unusual DNS queries or unexpected outbound connections. Deploying a reputable endpoint protection solution with behavioral analysis capabilities can help detect malware activity on devices connected to compromised routers. For organizations, segmenting legacy or IoT devices onto separate network VLANs can limit the blast radius should a router become infected.<\/p>\n<p>This incident underscores a critical cybersecurity reality: end-of-life hardware is a persistent and exploitable attack surface. Manufacturers stop issuing patches, but attackers continue to reverse-engineer and weaponize the vulnerabilities that remain unaddressed. Replacing unsupported devices is not a convenience \u2014 it is a necessary security measure.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A newly identified malware botnet designated AryStinger has compromised over 4,000 end-of-life routers worldwide, transforming them into remotely controlled proxies for scanning, tunneling, and command execution. Researchers at Qianxin&#8217;s XLab threat intelligence team discovered the botnet targeting D-Link DIR-850L and DIR-818LW devices through a trio of known vulnerabilities, raising serious concerns about the lingering risks [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":74000,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/iili.io\/CIEYKTx.jpg","fifu_image_alt":"AryStinger Botnet Infects Thousands of D-Link Routers Globally","footnotes":""},"categories":[349],"tags":[],"class_list":["post-57541","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/iili.io\/CIEYKTx.jpg","fifu_image_alt":"AryStinger Botnet Infects Thousands of D-Link Routers Globally","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/57541","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=57541"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/57541\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/74000"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=57541"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=57541"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=57541"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}