← All news

vulnerability

AryStinger Botnet Turns 4,000 Old D-Link Routers Into Proxies

2026-06-21

A freshly documented botnet called AryStinger has rounded up more than 4,000 ageing routers and put them to work as proxies, scanners and tunnels for whoever is running the operation. The discovery comes from Qianxin's XLab team, who concede they still cannot pin down who is behind it.

The targets will be familiar to anyone who has watched this corner of the threat landscape for a while. D-Link's DIR-850L and DIR-818LW routers, exploited through a mix of old flaws (CVE-2013-3307, CVE-2016-5681) and a newer one, CVE-2025-11837. These are the same models that ended up inside the AVrecon botnet Lumen disrupted back in 2023, which says something about how long these devices keep humming away in cupboards and ceiling cavities after the vendor has stopped caring.

What an infected router actually does

Once compromised, the device becomes what XLab calls an executor. The operator can take a large scanning job, chop it into pieces, and farm the work out across thousands of routers running in parallel. That makes the early reconnaissance phase of an attack both faster and considerably harder to trace, because the scans are not coming from one rented VPS, they are coming from residential IPs in dozens of countries.

Beyond scanning, AryStinger can:

  • Rewrite DNS settings to silently redirect browsing
  • Watch traffic flowing through the device
  • Act as a tunnel for further activity

Where the infections sit

The geography is lopsided. South Korea accounts for 48.5% of infections, China another 31.8%, with smaller clusters in Sweden, Malaysia and Singapore. Whether that reflects where these D-Link models sold best, or simply where they have been left to age in place the longest, is open to interpretation.

XLab also flagged a second variant, written in Go and aimed at NAS devices. This one is more capable out of the box: built-in scanning, internal reconnaissance, and the ability to execute shell commands or run Go, Java and Python source code directly. Its footprint is still small. The ambition is not.

The longer story

The interesting thing about AryStinger is not the malware itself. Botnets that herd consumer routers are not new, and the techniques on display here are mostly familiar. The interesting thing is the supply. Two specific D-Link models, declared end-of-life years ago, are still abundant enough to support a 4,000-node botnet, and that is just the slice one research team happened to find.

Vendors retire products on a schedule. Households and small offices do not. A router that boots up, hands out IP addresses and lets people watch Netflix is, from the owner's perspective, working perfectly. The fact that it has not had a firmware update since 2017 is invisible until someone like XLab publishes a map of where it has been quietly proxying scans.

For MSPs and IT teams, the practical question is whether anyone has a running inventory of the network gear sitting in the cupboards of branch offices, remote staff and client sites. End-of-life kit does not announce itself. It just keeps routing traffic, and increasingly, someone else's.

AryStinger Botnet Turns 4,000 Old D-Link Routers Into Proxies | RiskSense