Signal

AryStinger malware hijacks thousands of legacy D-Link routers to form proxy network

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-06-22 06:57 UTCUpdated 2026-06-22 15:22 UTC
rss
malwarebotnetrouterssecurityincident_response
Trend in the last 24h
Current brief openSource links open
This current signal is open on the public brief with summary, metadata, source links, and full evidence. Pro adds compare-over-time, alerts, exports, and workflow.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
Malwarebytes Threat Analysis
malwarebytes.com · malwarebytes.com · 2026-06-22 15:22 UTC
The Hacker News
thehackernews.com · thehackernews.com · 2026-06-22 06:57 UTC
limited source diversity in top sources
Overview

The AryStinger botnet has compromised over 4,300 end-of-life D-Link routers, primarily DIR-850L and DIR-818LW models, turning them into a distributed reconnaissance and proxy network.

Entities
D-LinkAryStinger
Score total
1.01
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
  • The number of infected routers is still rising, indicating an ongoing threat.
  • The malware exploits vulnerabilities disclosed 13 years ago, highlighting risks of unsupported devices.
  • Awareness can prompt users and organizations to mitigate risks by replacing or securing legacy routers.
Why it matters
  • Legacy routers remain vulnerable due to lack of security patches, enabling persistent botnet infections.
  • Compromised routers are used for reconnaissance and proxying, aiding attackers in hiding their activities.
  • The widespread infection risks user privacy and facilitates further cyberattacks.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
  • AryStinger malware has infected over 4,300 legacy D-Link routers worldwide, forming a reconnaissance and proxy network.
How sources frame it
  • Malwarebytes Threat Analysis: neutral
  • The Hacker News: neutral
All evidence
All evidence
Malwarebytes Threat Analysis
malwarebytes.com · malwarebytes.com · 2026-06-22 15:22 UTC
The Hacker News
thehackernews.com · thehackernews.com · 2026-06-22 06:57 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
  • malwarebytes.com (1)
  • thehackernews.com (1)
Top origin domains (this list)
  • malwarebytes.com (1)
  • thehackernews.com (1)