A newly discovered malware botnet called AryStinger has compromised over 4,000 outdated D-Link routers, repurposing the devices as proxies to facilitate large-scale malicious network scanning and traffic interception.
Key Points
- Researchers at Qianxin’s XLab identified AryStinger, which exploits known vulnerabilities including CVE-2013-3307 and CVE-2025-11837.
- The botnet primarily targets D-Link DIR-850L and DIR-818LW routers, with 48.5% of infections located in South Korea.
- Infected devices function as distributed executors, allowing attackers to perform command execution, DNS hijacking, and network reconnaissance.
- A secondary Go-based variant of the malware exists, specifically designed to target and compromise network-attached storage (NAS) systems.
- Security experts recommend replacing end-of-life hardware and disabling remote management panels to mitigate the risk of unauthorized device control.