HomeSecurityAryStinger botnet has infected thousands of D-Link routers

AryStinger botnet has infected thousands of D-Link routers

A new malware botnet, dubbed AryStinger, has raised alarm in the cybersecurity community after it managed to infect more than 4,000 unpatched routers and turn them into tools for conducting malicious activities online. The malware exploits old but still active security vulnerabilities, proving that unpatched network devices are still one of the weakest links in the digital chain.

AryStinger malware infected D-Link routers Linksys botnet detection

According to researchers at Qianxin’s XLab threat intelligence team , AryStinger turns infected devices into remotely controlled “executors .” In other words, attackers can use routers as intermediate stations to scan networks, hide the origin of internet traffic, create tunnels, execute commands, and perform a range of other offensive actions.

See also: The Netherlands disabled a botnet with 17 million infected devices

How the AryStinger botnet

The botnet architecture is designed in a way that allows large tasks to be distributed across thousands of infected devices. For example, a massive internet scanning operation can be broken into smaller parts and executed simultaneously by different routers, significantly increasing the effectiveness of the attacks and making it difficult to track down the perpetrators.

AryStinger exploits known security vulnerabilities, including CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837. The target devices are primarily the D-Link DIR-850L and D-Link DIR-818LW, devices that have reached the end of their life cycle and no longer receive security updates from the manufacturer.

Old routers remain easy targets

The phenomenon is not new. The same router models have been the focus of previous attacks (by the AVrecon that was dismantled in 2023). However, the emergence of AryStinger demonstrates that thousands of vulnerable devices remain connected to the internet, essentially functioning as “digital zombies” that can be exploited again by cybercriminals.

Qianxin's telemetry data shows that nearly half of the infections are in South Korea, which accounts for 48.5% of cases. It is followed by China with 31.8%, Sweden with 6.4%, Malaysia with 3.5% and Singapore with 2.5%.

AryStinger botnet has infected thousands of D-Link routers

Two different versions of the malware

Researchers have identified two different variants of AryStinger. The first is written in the C programming language and primarily targets older routers. The second, which is based on the Go language, focuses on NAS storage systems and has more advanced capabilities.

See also: Chinese JDY botnet uses over 1,500 compromised devices

The NAS version can scan IP and DNS addresses, execute commands, download additional payloads, and perform internal network reconnaissance. It also supports code execution in languages ​​such as Go, Java, and Python, giving attackers a lot of flexibility.

Researchers estimate that AryStinger's distributed DNS infrastructure could theoretically be used for large-scale attacks against DNS resolution servers, although no such incidents have been observed so far.

The great challenge of security in the Internet of Things

The AryStinger case brings to the fore a perennial problem in the Internet of Things. Millions of connected devices, from routers and security cameras to smart TVs and storage systems, continue to operate for years without security updates.

See also: Glassworm botnet collapses after C2 infrastructure is disrupted

AryStinger botnet has infected thousands of D-Link routers

For cybercriminals, these devices are ideal targets. They have limited protection mechanisms, users often ignore basic security practices, and default passwords often remain unchanged.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Experts recommend that users replace routers that have reached the end of their support, install all available firmware updates, promptly change factory passwords , and disable remote management when not necessary. In an era where every connected device can be turned into a cyberattack tool, home network security is no longer a luxury, but a basic requirement for digital protection.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS