A newly documented botnet called AryStinger infected more than 4,000 older D-Link routers and turned them into systems that relay malicious traffic and help attackers scan and probe other networks. XLab said the malware targets end-of-life D-Link DIR-850L and DIR-818LW devices by exploiting older flaws including CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837; researchers also found a Go-based variant aimed at network-attached storage systems. Infected devices can proxy traffic, tamper with Domain Name System settings, execute commands, and monitor network traffic.
Why it matters: People and organizations still using these unsupported routers may have their internet traffic monitored or redirected without noticing, and their devices can be used to help attack others. Replace end-of-life hardware, apply the latest firmware if any is available, change admin passwords, and disable remote management.
info@thehackernews.com (The Hacker News)
2026.06.22
99% relevant
This is the same underlying event: AryStinger infecting roughly 4,300 legacy D-Link routers to build a proxy and reconnaissance network for malicious use.
Bill Toulas
2026.06.21
100% relevant
This article appears to be the first concrete report establishing AryStinger as a distinct botnet campaign affecting thousands of D-Link routers worldwide.
← Back to all stories