AryStinger botnet hijacked more than 4,000 D-Link routers to act as attacker-controlled proxies

A newly documented botnet called AryStinger infected more than 4,000 older D-Link routers and turned them into systems that relay malicious traffic and help attackers scan and probe other networks. XLab said the malware targets end-of-life D-Link DIR-850L and DIR-818LW devices by exploiting older flaws including CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837; researchers also found a Go-based variant aimed at network-attached storage systems. Infected devices can proxy traffic, tamper with Domain Name System settings, execute commands, and monitor network traffic.
Why it matters: People and organizations still using these unsupported routers may have their internet traffic monitored or redirected without noticing, and their devices can be used to help attack others. Replace end-of-life hardware, apply the latest firmware if any is available, change admin passwords, and disable remote management.

Sources

AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
info@thehackernews.com (The Hacker News) 2026.06.22 99% relevant
This is the same underlying event: AryStinger infecting roughly 4,300 legacy D-Link routers to build a proxy and reconnaissance network for malicious use.
AryStinger botnet infected thousands of D-Link routers worldwide
Bill Toulas 2026.06.21 100% relevant
This article appears to be the first concrete report establishing AryStinger as a distinct botnet campaign affecting thousands of D-Link routers worldwide.
← Back to all stories