CVE Tools
Back to feed
Research AryStinger malware D-Link DIR-850L Qianxin network-edge

AryStinger botnet infected thousands of D-Link routers worldwide

BleepingComputer·By Bill Toulas··2 min read
CVE Tools coverage

Researchers report the AryStinger malware botnet has infected more than 4,000 outdated D-Link routers, turning them into remotely controlled “executors” used for scanning, proxying, tunneling, and command execution. The botnet targets devices with multiple known weaknesses, including CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837, with primary impact on D-Link DIR-850L and D-Link DIR-818LW. This matters because compromised routers can also tamper with DNS settings, hijack browsing, and monitor traffic for potential data theft or further intrusions.