Ботнет AryStinger заразил тысячи роутеров D-Link
Reported exploitedD-Link DIR-850LAryStingerD-Link DIR-818LWOur summary
Researchers from Qianxin XLab report that the previously unknown AryStinger botnet has already infected 4,000+ legacy routers worldwide and repurposes compromised devices as remotely controlled proxies. The malware targets D-Link routers including CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837-affected models such as D-Link DIR-850L and DIR-818LW, enabling distributed scanning, traffic tunneling, DNS changes, browser traffic redirection, and potential capture of incoming and outgoing network traffic. This matters because unpatched consumer networking devices can be leveraged at scale for reconnaissance and follow-on attacks, including a separate AryStinger variant aimed at NAS systems.
Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.