HomeSecurityAryStinger botnet turns old D-Link routers into attack proxies

AryStinger botnet turns old D-Link routers into attack proxies

AryStinger is the latest reminder that old routers do not quietly age out of relevance. Once a device stops receiving security updates, it can become useful infrastructure for someone else.

Qianxin’s XLab threat intelligence team has described AryStinger as a previously undocumented malware botnet tied to more than 4,000 compromised outdated routers, though that infection count has not been independently verified. The malware is said to turn vulnerable devices into remotely controlled executors that can help attackers scan targets, proxy traffic, tunnel connections, run commands, and support other intrusion activity.

That matters because routers sit at the edge of a network. If one is compromised, the attacker may not need to break into a laptop or server first. The router itself can become a foothold, a relay, or a quiet observation point for traffic moving in and out of the network.

What AryStinger appears to do

The core idea behind AryStinger is distribution. Instead of running all scanning from one place, the operator can divide scanning work into smaller jobs and send those jobs to many compromised devices. That can make early reconnaissance faster and harder to trace back to a single origin point.

XLab says infected routers can be used for several tasks:

  • Scanning internet targets for exposed or vulnerable systems
  • Proxying traffic through compromised devices
  • Creating tunnels for attacker-controlled communications
  • Executing commands on infected hardware
  • Potentially altering DNS behavior or monitoring network traffic

The DNS angle is especially concerning for normal users. If malware can tamper with DNS settings, it may be able to redirect browsing requests or interfere with where devices believe they are connecting. XLab also warned that the malware may be capable of watching inbound and outbound traffic, though the practical impact would depend on the device, network setup, and what traffic is encrypted.

Older D-Link models are the main concern

XLab identified D-Link DIR-850L and DIR-818LW routers as primary targets, with AryStinger said to use older vulnerabilities including CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837. Those exploit details should be treated as researcher-attributed findings rather than independently confirmed facts.

The same two D-Link router families have also been associated with earlier botnet activity, including AVrecon, which Lumen disrupted in 2023. That history fits a broader pattern in router malware: once a model becomes known as vulnerable and widely deployed, it can remain attractive to different malware operators for years.

XLab’s telemetry places a large share of observed AryStinger infections in South Korea, followed by China, Sweden, Malaysia, and Singapore. The reported country breakdown has not been independently verified, but it suggests the activity is not limited to one local network or one narrow region.

There may be a NAS-focused version too

XLab also found what it describes as two AryStinger variants: a C-based version focused mostly on outdated routers, and a Go-based version aimed at NAS systems. The NAS variant appears to have a smaller footprint, but XLab characterizes it as the more capable branch of the malware.

The NAS version is said to support IP and DNS scanning, command execution, payload execution, and internal network reconnaissance through open-source penetration testing tools. Those capabilities have not been independently verified, so they are best understood as reported malware analysis findings rather than confirmed real-world use at scale.

One notable detail is its reported support for running shell commands as well as Go, Java, and Python source code. In practice, source-code execution can be less straightforward than dropping a compiled binary because the target system needs the right language runtime and compilation can create more noise. That limitation may make some attacks less stealthy or less reliable, depending on the compromised device.

What router owners should do

The practical advice is simple: do not keep unsupported routers online unless there is no alternative. End-of-life hardware is a recurring target because vendors no longer ship fixes for newly abused flaws, and users often forget the device exists until something breaks.

Router owners should take these steps:

  1. Check whether the router model is still supported by the vendor.
  2. Install the latest available firmware update.
  3. Replace end-of-life routers with actively supported hardware.
  4. Change the default administrator password.
  5. Disable remote management unless it is absolutely required.
  6. Review DNS settings and reset them if they look unfamiliar.

Small offices should also treat routers and NAS systems as part of their security inventory, not background appliances. These devices often have long uptimes, weak monitoring, and broad access to internal traffic. That makes them useful to attackers and easy to overlook during routine patching.

AryStinger has not been attributed to a known threat group, and several details about the operation remain unclear. But the broader lesson is not mysterious: when network hardware falls out of support, it can keep working for users while quietly becoming useful to attackers.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular

POPULAR TAGS

- Advertisment -