惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 司徒正美
T
The Blog of Author Tim Ferriss
F
Fortinet All Blogs
Martin Fowler
Martin Fowler
罗磊的独立博客
The GitHub Blog
The GitHub Blog
L
LangChain Blog
A
About on SuperTechFans
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
D
DataBreaches.Net
宝玉的分享
宝玉的分享
U
Unit 42
阮一峰的网络日志
阮一峰的网络日志
Last Week in AI
Last Week in AI
N
Netflix TechBlog - Medium
The Cloudflare Blog
Microsoft Azure Blog
Microsoft Azure Blog
H
Help Net Security
美团技术团队
大猫的无限游戏
大猫的无限游戏
雷峰网
雷峰网
爱范儿
爱范儿
酷 壳 – CoolShell
酷 壳 – CoolShell
MongoDB | Blog
MongoDB | Blog

Malwarebytes

Kali365 phishing kit bypasses MFA and steals Microsoft logins Company bragged phone mics could listen to conversations. They couldn’t. Fake LinkedIn emails abuse Adobe to track victims Fake software on GitHub and SourceForge distribute Deno RAT 700+ education and tech websites hijacked in huge ClickFix malware campaign Scammers pretending to be Microsoft had help from US executives A week in security (May 18 – May 24) Update Chrome now: Critical bugs could let attackers run code Microsoft Defender vulnerabilities are being exploited in the wild TikTok, YouTube, and Roblox face scrutiny, but age gates won’t fix child safety Catch spyware in the act with Windows Webcam Monitoring Researchers left AI agents alone in a virtual town and watched it all unravel Fake malware-signing service Fox Tempest dismantled by Microsoft Firefox 151 packs big privacy upgrades into a small update Biometrics, diagnoses, and bank details exposed in major healthcare breach Facebook scam promises cheap Aldi meat boxes, steals payment info instead YouTube wants your face to fight deepfakes Microsoft is changing Edge’s plaintext password behavior A week in security (May 11 – May 17) AI is distorting the Holocaust (Lock and Code S07E10) Attackers replaced JDownloader installer downloads with malware Meta’s confusing new approach to chat privacy Why Malwarebytes blocks some Yahoo Mail redirects Deepfake sextortion forces schools to remove student photos from websites Texas sued Netflix over claims it secretly collected and sold users’ data May 2026 Patch Tuesday: no zero-days but plenty to fix Fake Claude search results lure Mac users into ClickFix attack 1 in 8 employees have sold company logins or know someone who has Stolen Canvas data was “returned” after hacker agreement, Instructure says Yarbo responds to robot flaws that could mow down their owners
Thousands of D-Link routers under control of AryStinger b...
Pieter Arntz · 2026-06-22 · via Malwarebytes

Researchers have found that the recently discovered AryStinger botnet has quietly hijacked thousands of end‑of‑life D‑Link routers and some network-attached storage (NAS) devices, turning them into a distributed scanning and proxy network that attackers can use to hide their activity and launch attacks against other targets. 

Having your devices under control of a botnet is not just a problem for the people being targeted. It can also put your own privacy and security at risk. 

The AryStinger botnet is mainly built on compromised D‑Link DIR‑850L and DIR‑818LW routers. Although these devices are long past end‑of‑life, they are still widely used in homes and small offices, making them attractive targets for botnet operators.

The attackers exploited vulnerabilities disclosed 13 years ago to compromise a large number of routers. According to the researchers:

“At least 4,300 routers worldwide have already been infected, and the number is still continuously rising.”

By targeting routers that are no longer supported by the vendor, the attackers gain access to devices that will never receive security patches but remain connected to the internet.

AryStinger turns each infected device into what the researchers call an “Executor”: a remotely controlled node that can scan networks, act as a proxy, create tunnels, and run commands on behalf of the attacker.

The botnet’s controller splits large reconnaissance tasks into many smaller ones and distributes them across these Executors, effectively turning a fleet of consumer routers into a large-scale scanning platform.

The botnet’s primary purpose is reconnaissance at scale. The controller can:

  • Push scanning jobs (for IP ranges, open ports, DNS records) down to many Executors in parallel.
  • Use those results to map networks, identify new vulnerable services, and prepare further compromises (“footprinting”).

For owners of infected devices, a more worrying capability is AryStinger’s ability to tamper with DNS settings. This allows attackers to:

  • Redirect victims’ browser traffic to phishing pages or malware‑hosting sites.
  • Silently monitor and potentially steal all inbound and outbound network traffic passing through the router or NAS.

This can put otherwise well-protected devices at risk. Mobile phones, tablets, and laptops connected to the compromised router can be redirected as well.

How to tell if you’re impacted

For owners of an affected router or NAS, the immediate signs may be subtle or non‑existent. Possible indicators might be:

  • Slightly slower connectivity
  • Occasional unexplained DNS failures or redirects
  • Spikes in outbound traffic at odd times

But the underlying risks are serious enough:

  • Privacy: Attackers may be able to inspect or redirect your traffic, potentially capturing usernames, passwords, session cookies, or other sensitive data.
  • Liability and reputation: Your IP address could be used for fraud, credential‑stuffing, harassment, or other criminal activity, potentially attracting attention from service providers or law enforcement—something already seen in other proxy botnets.
  • Pivoting into your network: Particularly on compromised NAS devices, attackers may be able to map internal networks and look for additional systems to target.

What to do

This is not the first time attackers have built a botnet from abandoned networking equipment. Unfortunately, the most effective solution is also the least popular one: Replace end-of-life routers and NAS devices.

If that’s not an immediate option, there are some steps you can take to make your device harder to compromise:

  • Apply the latest firmware available for your device, even if it’s old, and review any vendor security advisories for known vulnerabilities.
  • Change the default administrator password to a unique, strong password or passphrase; never reuse passwords from other accounts.
  • Disable remote management from the internet (WAN). Only access the admin interface from inside your home or office network.
  • Use WPA2 or WPA3 wireless encryption and a strong Wi‑Fi password to reduce the chance of local abuse.
  • If your router supports it, turn off unused services such as UPnP on the WAN side or legacy remote access protocols.
  • Run an anti-malware scan on computers and other devices connected to the router to check whether any were separately infected while traffic was being tampered with.

Even if you apply all of these recommendations, an end-of-life router should be considered untrusted. Make plans to replace it as soon as you can.


We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

About the author

Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.