AryStinger botnet infected thousands of D-Link routers worldwide
ResearchAryStingerD-Link DIR-850LOur summary
Researchers report the AryStinger malware botnet has infected more than 4,000 outdated D-Link routers, turning them into remotely controlled “executors” used for scanning, proxying, tunneling, and command execution. The botnet targets devices with multiple known weaknesses, including CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837, with primary impact on D-Link DIR-850L and D-Link DIR-818LW. This matters because compromised routers can also tamper with DNS settings, hijack browsing, and monitor traffic for potential data theft or further intrusions.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.