AryStinger botnet infected thousands of D-Link routers worldwide
Security researchers have disclosed AryStinger, a new botnet that has infected over 4,000 outdated D-Link routers to form a distributed network of executors for scanning, proxying, tunneling, and remote command execution. Two variants were found: a C-based version targeting legacy routers and a Go-based NAS-focused version with broader capabilities, including IP/DNS scanning and internal reconnaissance; infections are concentrated in South Korea (about 48%), followed by China (about 32%). The malware exploits CVEs 2013-3307, 2016-5681, and 2025-11837 and primarily targets D-Link DIR-850L and DIR-818LW devices. Researchers warn of DNS tampering and traffic monitoring, though attribution remains unclear. Defenders are advised to retire end-of-life routers, apply the latest firmware, change default passwords, and disable remote management.

AryStinger Botnet Infected Thousands of D-Link Routers Worldwide
OverviewA previously undocumented malware botnet has emerged, dramatically expanding its reach by turning outdated consumer routers into remote proxies for illicit activities. Researchers describe AryStinger as a distributed, multi-scalar threat that can orchestrate large-scale scanning, proxying, tunneling, and remote command execution from compromised devices. The net effect is a flexible, scalable platform that enables attackers to fragment tasks into smaller chunks and process them in parallel across many “Executor” devices.
Infection Scope and Affected Devices
- Size and scope: AryStinger has compromised more than four thousand routers that were no longer receiving active support or security updates.
- Targeted models: The malware primarily targeted older D-Link devices, notably the DIR-850L and the DIR-818LW series.
- Legacy focus: The emphasis on aging hardware highlights the risk posed by end-of-life networking gear that remains in widespread household use.
How AryStinger Works
- Distributed execution model: The attacker distributes scanning and reconnaissance tasks across a network of infected devices, enabling parallel execution and faster overall operations.
- Remote control architecture: Infected devices act as executors that can be commanded to perform scanning, proxying, tunneling, and execution of payloads.
- Footprinting and intrusions: The design supports early-stage footprinting to improve the chances of successful intrusions in subsequent steps.
- DNS and traffic tampering risk: Beyond enabling malicious traffic, AryStinger can potentially alter DNS settings to hijack user browsing and silently monitor or exfiltrate network traffic.
Variants and Capabilities
- C-based variant: This version targets older routers and forms the core of AryStinger’s router-focused operations.
- Go-based NAS variant: Focused on network-attached storage devices, this variant represents a more advanced line of capabilities and a broader attack surface, though its reach is currently more limited than the router-focused version.
- NAS capabilities:
- IP and DNS scanning
- Command execution and payload deployment
- Internal network reconnaissance using open-source penetration testing tools
- Code execution: The NAS variant supports executing commands in multiple languages (Shell, Go, Java, Python), expanding the types of payloads or scripts it can run.
- Operational trade-offs: When using source code rather than precompiled binaries, the need for language runtimes and the potential for stealth-related noise can complicate the execution and concealment of payloads.
Targeted Vulnerabilities and Historical Context
- Exploited CVEs: AryStinger leverages known flaws to gain a foothold, including CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837.
- Previous campaigns: The router models affected by AryStinger had also been targeted in prior campaigns, underscoring persistent risk from aging devices in active networks.
- Relationship to older botnets: AryStinger continues a pattern of leveraging legacy devices to form large-scale botnets that can be rented or repurposed for various malicious tasks.
Geographic Footprint and Telemetry
- Leading infection region: South Korea accounts for roughly half of all identified infections (about 48.5%).
- Secondary regions: China (approximately 31.8%), Sweden (about 6.4%), Malaysia (roughly 3.5%), and Singapore (around 2.5%).
- Telemetry source: These percentages come from threat intelligence observations that track the distribution of infected devices and provide insight into where AryStinger’s activity is most concentrated.
Technical Nuances and Observations
- Infected device behavior: An infected router can establish command-and-control (C2) communications and participate in distributed tasks that support larger malicious operations.
- C2 and persistence: The architecture supports ongoing control and coordination between executors, enabling sustained activity across the compromised fleet.
- Stealth considerations: The Go-based NAS variant introduces additional capabilities, but the need to compile code at runtime can introduce operational noise that may affect stealth in some environments.
- Open questions: Many mysteries remain about AryStinger’s full actor set, operational scope, and whether it is tied to an organized group or operates as a loosely affiliated collection of actors.
Context and Open Questions for Researchers
- Open-ended risk: AryStinger exemplifies how adversaries can leverage aging home networking gear to build resilient, distributed attack platforms.
- Potential future evolutions: As attackers refine their tooling, there may be shifts toward broader NAS targets, more sophisticated payloads, or enhanced evasion techniques.
- Research gaps: While telemetry provides insight into distributions and capabilities, the full extent of AryStinger’s command structure, second-stage payloads, and long-term persistence strategies remain to be fully uncovered.
Concluding ObservationsAryStinger represents a significant development in the landscape of botnets that exploit legacy hardware. By combining a distributed execution model with multi-language payload support and a focus on both routers and NAS devices, this threat demonstrates how outdated devices can be repurposed into powerful infrastructure for malicious operations. The ongoing analysis by threat intelligence teams continues to shed light on how such botnets evolve, the vulnerabilities they exploit, and the broad implications for home and small-business networks that still rely on aging equipment.


