AryStinger botnet turns outdated routers into proxy executors
Malware Activity
Summary
Hide ▲
Show ▼
The AryStinger botnet is compromising more than 4,000 outdated routers and converting them into proxy executors for malicious traffic, expanding attacker reach and interception risk. It targets D-Link DIR-850L and D-Link DIR-818LW routers through older flaws and can support scanning, tunneling, and command execution. The malware also enables DNS tampering and network-traffic monitoring, creating a broader exposure window for affected networks.
Related Happenings
AryStinger legacy-router reconnaissance and proxy network
Malware Activity
H score61
First: 22.06.2026 09:57
Last: 22.06.2026 09:57
Sources 1
About this happening:
The AryStinger malware family is building a distributed reconnaissance and proxy network from legacy routers and NAS appliances, expanding a covert relay layer that helps...
AryStinger legacy-router reconnaissance and proxy network
Malware ActivityAbout this happening: The AryStinger malware family is building a distributed reconnaissance and proxy network from legacy routers and NAS appliances, expanding a covert relay layer that helps...
AryStinger legacy-router and QNAP NAS reconnaissance campaign
Campaign
H score72
First: 22.06.2026 09:57
Last: 22.06.2026 09:57
Sources 1
About this happening:
The AryStinger campaign is turning legacy routers and QNAP NAS boxes into a distributed reconnaissance and proxy network, creating a stealth relay layer for intrus...
AryStinger legacy-router and QNAP NAS reconnaissance campaign
CampaignAbout this happening: The AryStinger campaign is turning legacy routers and QNAP NAS boxes into a distributed reconnaissance and proxy network, creating a stealth relay layer for intrus...
Forest Blizzard DNS hijacking token-theft campaign against older routers
Campaign
H score35
First: 07.04.2026 20:02
Last: 07.04.2026 20:02
Sources 1
About this happening:
Russia-backed Forest Blizzard is running a DNS hijacking campaign against older routers to steal Microsoft Office authentication tokens, putting accounts at risk acros...
Forest Blizzard DNS hijacking token-theft campaign against older routers
CampaignAbout this happening: Russia-backed Forest Blizzard is running a DNS hijacking campaign against older routers to steal Microsoft Office authentication tokens, putting accounts at risk acros...
AVRecon malware for Linux powering SocksEscort proxy network
Malware Activity
H score19
First: 12.03.2026 18:19
Last: 12.03.2026 18:19
Sources 1
About this happening:
The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...
AVRecon malware for Linux powering SocksEscort proxy network
Malware ActivityAbout this happening: The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...
KadNap botnet turns ASUS routers into residential proxies
Malware Activity
H score23
First: 10.03.2026 17:01
Last: 10.03.2026 17:01
Sources 1
About this happening:
The KadNap botnet is now compromising ASUS routers and other edge networking devices, turning them into residential proxies that can hide malicious traffic. The networ...
KadNap botnet turns ASUS routers into residential proxies
Malware ActivityAbout this happening: The KadNap botnet is now compromising ASUS routers and other edge networking devices, turning them into residential proxies that can hide malicious traffic. The networ...
Timeline
-
21.06.2026 17:14 2 articles · 24d ago
Qianxin XLab identifies AryStinger botnet compromising more than 4,000 outdated routers
Initial DisclosureQianxin XLab identifies the previously undocumented AryStinger botnet, which has compromised more than 4,000 outdated routers and converted them into remotely controlled executors for scanning, proxying, tunneling, command execution, DNS tampering, and traffic interception. The malware primarily targets D-Link DIR-850L and D-Link DIR-818LW routers by exploiting CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837, and XLab also found a Go-based variant that focuses on NAS systems.
Show sources
- AryStinger botnet infected thousands of D-Link routers worldwide — www.bleepingcomputer.com — 21.06.2026 17:14
- AryStinger botnet infected thousands of D-Link routers worldwide — www.bleepingcomputer.com — 21.06.2026 17:14