AryStinger botnet turns outdated routers into proxy executors
Malware Activity
Updated: 21.06.2026 17:14
· First: 21.06.2026 17:14
· 📰 1 src / 1 articles
· H score: 60
The AryStinger botnet is compromising more than 4,000 outdated routers and converting them into proxy executors for malicious traffic, expanding attacker reach and interception risk. It targets D-Link DIR-850L and D-Link DIR-818LW routers through older flaws and can support scanning, tunneling, and command execution. The malware also enables DNS tampering and network-traffic monitoring, creating a broader exposure window for affected networks.