Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Thieves Stole ‘Nvidia’ Trailers. They Got 20 Tons of Sand

    September 25, 2026

    Appeals Court Lets the Pentagon Designate Anthropic a Supply-Chain Risk

    September 25, 2026

    Young organs may not be a fountain of youth for recipients

    September 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Thieves Stole ‘Nvidia’ Trailers. They Got 20 Tons of Sand
    • Appeals Court Lets the Pentagon Designate Anthropic a Supply-Chain Risk
    • Young organs may not be a fountain of youth for recipients
    • How Would AI Actually Kill All Humans? Here Are the Top 5 Scenarios
    • Social Media Bans for Kids Need Smarter Safety Design
    • The Pentagon wants $30 million to build an AI-powered lie detector
    • Google’s Gemini Can Now Make Calls for You on Pixel Phones
    • EPICS in IEEE Team Builds Portable Educational Platform
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»AryStinger botnet infected thousands of D-Link routers worldwide
    Cybersecurity

    AryStinger botnet infected thousands of D-Link routers worldwide

    kirklandc008@gmail.comBy kirklandc008@gmail.comJune 21, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Botnet
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A previously undocumented malware botnet named AryStinger has compromised more than 4,000 outdated routers to turn them into proxies for malicious traffic.

    Researchers at Qianxin’s XLab threat intelligence team say that the malware converts infected devices into remotely controlled “executors” that can perform scanning, proxying, tunneling, command execution, and other activities on behalf of the attacker.

    “The attacker can split a massive scanning task into multiple small chunks and distribute them to different Executors for parallel execution,” XLab researchers note.

    “With this distributed-like design, the attacker can efficiently complete the early “footprinting” activities, thereby providing strong assurance for the smoothness and success rate of subsequent intrusion operations.”

    Apart from using compromised routers as a springboard for malicious operations, XLab warns that the malware can also tamper with DNS settings, hijacking the user’s browsing, and silently monitor and potentially steal all inbound and outbound network traffic.

    Server distributing AryStinger scan jobs
    Source: XLab

    AryStinger exploits older flaws such as CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837, targeting primarily D-Link DIR-850L, D-Link DIR-818LW routers.

    The two router models were previously targeted by the AVrecon malware botnet that Lumen communications services provider Lumen disrupted in 2023.

    Qianxin’s telemetry data shows that almost half of all infections are located in South Korea (48.5%), followed by China (31.8%), Sweden (6.4%), Malaysia (3.5%), and Singapore (2.5%).

    XLab researchers found two variants of the AryStinger malware: a C-based version targeting mostly outdated routers, and a Go-based one that focuses on NAS systems, but currently with a far more limited reach.

    Infected router establishing C2 communication
    Source: XLab

    The NAS version is the most advanced of the two, featuring additional capabilities such as IP and DNS scanning, command execution, payload execution, and internal network reconnaissance through the integration of open-source penetration testing tools.

    The researchers noted that AryStinger’s distributed DNS-scanning infrastructure could potentially be repurposed to generate large volumes of DNS queries against resolvers, although they did not observe any such attacks.

    Regarding the NAS version’s code execution capabilities, XLab says there’s support for Shell commands, as well as Go, Java, and Python source code.

    However, there are some limitations to using source code instead of compiled binaries, as compilation requires language runtimes on the host, and the process as a whole introduces noise that can break stealth.

    The researchers did not attribute AryStinger to any known activity cluster, stating that “many mysteries surrounding AryStinger remain to be solved.”

    Owners of end-of-life (EoL) routers should replace them with new, actively supported models, apply the latest available firmware updates, change the default administrator account password, and disable remote management panels.

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    AryStinger botnet DLink Infected routers Thousands worldwide
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Thieves Stole ‘Nvidia’ Trailers. They Got 20 Tons of Sand
    • Appeals Court Lets the Pentagon Designate Anthropic a Supply-Chain Risk
    • Young organs may not be a fountain of youth for recipients
    • How Would AI Actually Kill All Humans? Here Are the Top 5 Scenarios
    • Social Media Bans for Kids Need Smarter Safety Design

    Thieves Stole ‘Nvidia’ Trailers. They Got 20 Tons of Sand

    September 25, 2026

    Appeals Court Lets the Pentagon Designate Anthropic a Supply-Chain Risk

    September 25, 2026

    Young organs may not be a fountain of youth for recipients

    September 25, 2026

    How Would AI Actually Kill All Humans? Here Are the Top 5 Scenarios

    September 25, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.