LIVE NEWS
  • GTA 6 early access offers are taking gamers’ crypto
  • How to turn computing power into a financial asset
  • Energy security is back—and other top takeaways from the Atlantic Council’s biggest-ever energy forum
  • Ask Stuart Kirk a question: Where should I invest?
  • House to vote on landmark bill that boosts DOD and VA benefits for some while cutting others
  • Red squirrel sickness reports in Tweeddale under investigation
  • Turkey detains 209 in raids in the capital ahead of July’s NATO summit
  • US Senate Passes Housing Bill With Four-Year Fed CBDC Ban
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»AryStinger botnet infected thousands of D-Link routers worldwide
Cybersecurity

AryStinger botnet infected thousands of D-Link routers worldwide

primereportsBy primereportsJune 22, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
AryStinger botnet infected thousands of D-Link routers worldwide
Share
Facebook Twitter LinkedIn Pinterest Email


AryStinger botnet infected thousands of D-Link routers worldwide

A previously undocumented malware botnet named AryStinger has compromised more than 4,000 outdated routers to turn them into proxies for malicious traffic.

Researchers at Qianxin’s XLab threat intelligence team say that the malware converts infected devices into remotely controlled “executors” that can perform scanning, proxying, tunneling, command execution, and other activities on behalf of the attacker.

“The attacker can split a massive scanning task into multiple small chunks and distribute them to different Executors for parallel execution,” XLab researchers note.

image

“With this distributed-like design, the attacker can efficiently complete the early “footprinting” activities, thereby providing strong assurance for the smoothness and success rate of subsequent intrusion operations.”

Apart from using compromised routers as a springboard for malicious operations, XLab warns that the malware can also tamper with DNS settings, hijacking the user’s browsing, and silently monitor and potentially steal all inbound and outbound network traffic.

Server distributing AryStinger scan jobs
Server distributing AryStinger scan jobs
Source: XLab

AryStinger exploits older flaws such as CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837, targeting primarily D-Link DIR-850L, D-Link DIR-818LW routers.

The two router models were previously targeted by the AVrecon malware botnet that Lumen communications services provider Lumen disrupted in 2023.

Qianxin’s telemetry data shows that almost half of all infections are located in South Korea (48.5%), followed by China (31.8%), Sweden (6.4%), Malaysia (3.5%), and Singapore (2.5%).

XLab researchers found two variants of the AryStinger malware: a C-based version targeting mostly outdated routers, and a Go-based one that focuses on NAS systems, but currently with a far more limited reach.

Infected router establishing C2 communication
Infected router establishing C2 communication
Source: XLab

The NAS version is the most advanced of the two, featuring additional capabilities such as IP and DNS scanning, command execution, payload execution, and internal network reconnaissance through the integration of open-source penetration testing tools.

The researchers noted that AryStinger’s distributed DNS-scanning infrastructure could potentially be repurposed to generate large volumes of DNS queries against resolvers, although they did not observe any such attacks.

Regarding the NAS version’s code execution capabilities, XLab says there’s support for Shell commands, as well as Go, Java, and Python source code.

However, there are some limitations to using source code instead of compiled binaries, as compilation requires language runtimes on the host, and the process as a whole introduces noise that can break stealth.

The researchers did not attribute AryStinger to any known activity cluster, stating that “many mysteries surrounding AryStinger remain to be solved.”

Owners of end-of-life (EoL) routers should replace them with new, actively supported models, apply the latest available firmware updates, change the default administrator account password, and disable remote management panels.


article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleSoftware Engineers Face an AI ‘Identity Crisis,’ VC Partner Says
Next Article Tom Lee Says ‘Zero Chance’ of Ethereum Funding Crisis as Insider Warns of $30M Gap
primereports
  • Website

Related Posts

Cybersecurity

GTA 6 early access offers are taking gamers’ crypto

June 23, 2026
Cybersecurity

Court rules SAVE database illegal, orders it dismantled

June 22, 2026
Cybersecurity

GentleKiller Framework Disables Victims’ Security Software

June 22, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202616 Views

Global Resources Outlook 2024 | UNEP

December 6, 202510 Views

Texas Democrat Talarico claims voting laws are rigged ahead of Paxton race

May 28, 20269 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • GTA 6 early access offers are taking gamers’ crypto
  • How to turn computing power into a financial asset
  • Energy security is back—and other top takeaways from the Atlantic Council’s biggest-ever energy forum
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.