CVE Tools

AryStinger botnet infected thousands of D-Link routers worldwide

BleepingComputerBy Bill Toulas

ResearchAryStingerD-Link DIR-850L

Our summary

Researchers report the AryStinger malware botnet has infected more than 4,000 outdated D-Link routers, turning them into remotely controlled “executors” used for scanning, proxying, tunneling, and command execution. The botnet targets devices with multiple known weaknesses, including CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837, with primary impact on D-Link DIR-850L and D-Link DIR-818LW. This matters because compromised routers can also tamper with DNS settings, hijack browsing, and monitor traffic for potential data theft or further intrusions.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store