AUTO-UPDATED

AryStinger botnet infected thousands of D-Link routers worldwide

A newly discovered malware botnet called AryStinger has compromised over 4,000 outdated D-Link routers, repurposing the devices as proxies to facilitate large-scale malicious network scanning and traffic interception.

Key Points

  • Researchers at Qianxin’s XLab identified AryStinger, which exploits known vulnerabilities including CVE-2013-3307 and CVE-2025-11837.
  • The botnet primarily targets D-Link DIR-850L and DIR-818LW routers, with 48.5% of infections located in South Korea.
  • Infected devices function as distributed executors, allowing attackers to perform command execution, DNS hijacking, and network reconnaissance.
  • A secondary Go-based variant of the malware exists, specifically designed to target and compromise network-attached storage (NAS) systems.
  • Security experts recommend replacing end-of-life hardware and disabling remote management panels to mitigate the risk of unauthorized device control.

Why it Matters

This campaign highlights the persistent security risks posed by end-of-life networking equipment that no longer receives official firmware updates. By leveraging these vulnerable devices, attackers can build resilient, distributed infrastructures to mask malicious activity and conduct large-scale cyber operations.
BleepingComputer Published by Bill Toulas
Read original