Find notable cyber news and cases, enriched with sources, timelines, and signals.

AryStinger botnet turns outdated routers into proxy executors

Malware Activity
First reported
Last updated
Happening score
H score 60
1 unique sources, 1 articles

Summary

Hide ▲

The AryStinger botnet is compromising more than 4,000 outdated routers and converting them into proxy executors for malicious traffic, expanding attacker reach and interception risk. It targets D-Link DIR-850L and D-Link DIR-818LW routers through older flaws and can support scanning, tunneling, and command execution. The malware also enables DNS tampering and network-traffic monitoring, creating a broader exposure window for affected networks.

Related Happenings

AryStinger legacy-router reconnaissance and proxy network

Malware Activity
H score61 First: 22.06.2026 09:57 Last: 22.06.2026 09:57 Sources 1

About this happening: The AryStinger malware family is building a distributed reconnaissance and proxy network from legacy routers and NAS appliances, expanding a covert relay layer that helps...

AryStinger legacy-router and QNAP NAS reconnaissance campaign

Campaign
H score72 First: 22.06.2026 09:57 Last: 22.06.2026 09:57 Sources 1

About this happening: The AryStinger campaign is turning legacy routers and QNAP NAS boxes into a distributed reconnaissance and proxy network, creating a stealth relay layer for intrus...

Forest Blizzard DNS hijacking token-theft campaign against older routers

Campaign
H score35 First: 07.04.2026 20:02 Last: 07.04.2026 20:02 Sources 1

About this happening: Russia-backed Forest Blizzard is running a DNS hijacking campaign against older routers to steal Microsoft Office authentication tokens, putting accounts at risk acros...

AVRecon malware for Linux powering SocksEscort proxy network

Malware Activity
H score19 First: 12.03.2026 18:19 Last: 12.03.2026 18:19 Sources 1

About this happening: The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...

KadNap botnet turns ASUS routers into residential proxies

Malware Activity
H score23 First: 10.03.2026 17:01 Last: 10.03.2026 17:01 Sources 1

About this happening: The KadNap botnet is now compromising ASUS routers and other edge networking devices, turning them into residential proxies that can hide malicious traffic. The networ...

Timeline

  1. 21.06.2026 17:14 2 articles · 24d ago

    Qianxin XLab identifies AryStinger botnet compromising more than 4,000 outdated routers

    Initial Disclosure

    Qianxin XLab identifies the previously undocumented AryStinger botnet, which has compromised more than 4,000 outdated routers and converted them into remotely controlled executors for scanning, proxying, tunneling, command execution, DNS tampering, and traffic interception. The malware primarily targets D-Link DIR-850L and D-Link DIR-818LW routers by exploiting CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837, and XLab also found a Go-based variant that focuses on NAS systems.

    Show sources