{"id":64783,"date":"2026-06-22T11:53:48","date_gmt":"2026-06-22T11:53:48","guid":{"rendered":"https:\/\/zero.redgem.net\/?p=64783"},"modified":"2026-06-22T11:53:48","modified_gmt":"2026-06-22T11:53:48","slug":"thousands-of-d-link-routers-under-control-of-arystinger-botnet","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=64783","title":{"rendered":"Thousands of D-Link routers under control of AryStinger botnet_MALWAREBYTES:A0D999B5D88190CE5F2B8E2C477AAC4E"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-06-22T15:36:51&#8243;,&#8221;description&#8221;:&#8221;Researchers have found that the recently discovered AryStinger botnet has quietly hijacked thousands of end\u2011of\u2011life D\u2011Link routers and some network-attached storage (NAS) devices, turning them into a distributed scanning and proxy network that attackers can use to hide their activity and launch attacks against other targets. \\n\\nHaving your devices under control of a botnet is not just a problem for the people being targeted. It can also put your own privacy and security at risk. \\n\\nThe AryStinger botnet is mainly built on compromised D\u2011Link DIR\u2011850L and DIR\u2011818LW routers. Although these devices are long past end\u2011of\u2011life, they are still widely used in homes and small offices, making them attractive targets for botnet operators. \\n\\nThe attackers exploited vulnerabilities disclosed 13 years ago to compromise a large number of routers. According to the researchers:\\n\\n\\u003e \u201cAt least 4,300 routers worldwide have already been infected, and the number is still continuously rising.\u201d\\n\\nBy targeting routers that are no longer supported by the vendor, the attackers gain access to devices that will never receive security patches but remain connected to the internet.\\n\\nAryStinger turns each infected device into what the researchers call an \u201cExecutor\u201d: a remotely controlled node that can scan networks, act as a proxy, create tunnels, and run commands on behalf of the attacker. \\n\\nThe botnet\u2019s controller splits large reconnaissance tasks into many smaller ones and distributes them across these Executors, effectively turning a fleet of consumer routers into a large-scale scanning platform.\\n\\nThe botnet&#8217;s primary purpose is reconnaissance at scale. The controller can:\\n\\n  * Push scanning jobs (for IP ranges, open ports, DNS records) down to many Executors in parallel.\\n  * Use those results to map networks, identify new vulnerable services, and prepare further compromises (\u201cfootprinting\u201d).\\n\\n\\n\\nFor owners of infected devices, a more worrying capability is AryStinger&#8217;s ability to tamper with DNS settings. This allows attackers to:\\n\\n  * Redirect victims\u2019 browser traffic to phishing pages or malware\u2011hosting sites.\\n  * Silently monitor and potentially steal all inbound and outbound network traffic passing through the router or NAS.\\n\\n\\n\\nThis can put otherwise well-protected devices at risk. Mobile phones, tablets, and laptops connected to the compromised router can be redirected as well.\\n\\n## How to tell if you&#8217;re impacted\\n\\nFor owners of an affected router or NAS, the immediate signs may be subtle or non\u2011existent. Possible indicators might be:\\n\\n  * Slightly slower connectivity\\n  * Occasional unexplained DNS failures or redirects\\n  * Spikes in outbound traffic at odd times\\n\\n\\n\\nBut the underlying risks are serious enough:\\n\\n  * **Privacy:** Attackers may be able to inspect or redirect your traffic, potentially capturing usernames, passwords, session cookies, or other sensitive data.\\n  * **Liability and reputation:** Your IP address could be used for fraud, credential\u2011stuffing, harassment, or other criminal activity, potentially attracting attention from service providers or law enforcement\u2014something already seen in other proxy botnets.\\n  * **Pivoting into your network:** Particularly on compromised NAS devices, attackers may be able to map internal networks and look for additional systems to target.\\n\\n\\n\\n## What to do\\n\\nThis is not the first time attackers have built a botnet from abandoned networking equipment. Unfortunately, the most effective solution is also the least popular one: Replace end-of-life routers and NAS devices. \\n\\nIf that\u2019s not an immediate option, there are some steps you can take to make your device harder to compromise:\\n\\n  * **Apply the latest firmware** available for your device, even if it\u2019s old, and review any vendor security advisories for known vulnerabilities.\\n  * **Change the default administrator password**  to a unique, strong password or passphrase; never reuse passwords from other accounts.\\n  * **Disable remote management** from the internet (WAN). Only access the admin interface from inside your home or office network.\\n  * **Use WPA2 or WPA3**  wireless encryption and a strong Wi\u2011Fi password to reduce the chance of local abuse.\\n  * If your router supports it, **turn off unused services**  such as UPnP on the WAN side or legacy remote access protocols.\\n  * Run an **anti-malware scan** on computers and other devices connected to the router to check whether any were separately infected while traffic was being tampered with.\\n\\n\\n\\nEven if you apply all of these recommendations, an end-of-life router should be considered untrusted. Make plans to replace it as soon as you can.\\n\\n* * *\\n\\n**We don\u2019t just report on threats\u2014we remove them**\\n\\nCybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.&#8221;,&#8221;published&#8221;:&#8221;2026-06-22T15:22:22&#8243;,&#8221;modified&#8221;:&#8221;2026-06-22T15:22:22&#8243;,&#8221;type&#8221;:&#8221;malwarebytes&#8221;,&#8221;title&#8221;:&#8221;Thousands of D-Link routers under control of AryStinger botnet&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;MALWAREBYTES:A0D999B5D88190CE5F2B8E2C477AAC4E&#8221;,&#8221;bulletinFamily&#8221;:&#8221;blog&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/www.malwarebytes.com\/blog\/news\/2026\/06\/thousands-of-d-link-routers-under-control-of-arystinger-botnet&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-06-22T15:36:51&#8243;,&#8221;description&#8221;:&#8221;Researchers have found that the recently discovered AryStinger botnet has quietly hijacked thousands of end\u2011of\u2011life D\u2011Link routers and some network-attached storage (NAS) devices, turning them&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,12,115,13,33,7,11,5],"class_list":["post-64783","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-exploit","tag-malwarebytes","tag-news","tag-none","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Thousands of D-Link routers under control of AryStinger botnet_MALWAREBYTES:A0D999B5D88190CE5F2B8E2C477AAC4E - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=64783\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Thousands of D-Link routers under control of AryStinger botnet_MALWAREBYTES:A0D999B5D88190CE5F2B8E2C477AAC4E - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-06-22T15:36:51&#8243;,&#8221;description&#8221;:&#8221;Researchers have found that the recently discovered AryStinger botnet has quietly hijacked thousands of end\u2011of\u2011life D\u2011Link routers and some network-attached storage (NAS) devices, turning them...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=64783\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-22T11:53:48+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=64783#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=64783\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Thousands of D-Link routers under control of AryStinger botnet_MALWAREBYTES:A0D999B5D88190CE5F2B8E2C477AAC4E\",\"datePublished\":\"2026-06-22T11:53:48+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=64783\"},\"wordCount\":914,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"malwarebytes\",\"news\",\"NONE\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=64783#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=64783\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=64783\",\"name\":\"Thousands of D-Link routers under control of AryStinger botnet_MALWAREBYTES:A0D999B5D88190CE5F2B8E2C477AAC4E - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-06-22T11:53:48+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=64783#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=64783\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=64783#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Thousands of D-Link routers under control of AryStinger botnet_MALWAREBYTES:A0D999B5D88190CE5F2B8E2C477AAC4E\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Thousands of D-Link routers under control of AryStinger botnet_MALWAREBYTES:A0D999B5D88190CE5F2B8E2C477AAC4E - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=64783","og_locale":"en_US","og_type":"article","og_title":"Thousands of D-Link routers under control of AryStinger botnet_MALWAREBYTES:A0D999B5D88190CE5F2B8E2C477AAC4E - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-06-22T15:36:51&#8243;,&#8221;description&#8221;:&#8221;Researchers have found that the recently discovered AryStinger botnet has quietly hijacked thousands of end\u2011of\u2011life D\u2011Link routers and some network-attached storage (NAS) devices, turning them...","og_url":"https:\/\/zero.redgem.net\/?p=64783","og_site_name":"zero redgem","article_published_time":"2026-06-22T11:53:48+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=64783#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=64783"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Thousands of D-Link routers under control of AryStinger botnet_MALWAREBYTES:A0D999B5D88190CE5F2B8E2C477AAC4E","datePublished":"2026-06-22T11:53:48+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=64783"},"wordCount":914,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","malwarebytes","news","NONE","Security","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=64783#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=64783","url":"https:\/\/zero.redgem.net\/?p=64783","name":"Thousands of D-Link routers under control of AryStinger botnet_MALWAREBYTES:A0D999B5D88190CE5F2B8E2C477AAC4E - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-06-22T11:53:48+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=64783#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=64783"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=64783#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Thousands of D-Link routers under control of AryStinger botnet_MALWAREBYTES:A0D999B5D88190CE5F2B8E2C477AAC4E"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/64783","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=64783"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/64783\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=64783"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=64783"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=64783"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}