Skip to content
AryStinger Botnet Compromises Over 4,300 D-Link Routers for Reconnaissance

AryStinger Botnet Compromises Over 4,300 D-Link Routers for Reconnaissance

First seen 21 Jun 2026, 16:03 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 22, 2026 at 15:42 UTC

The AryStinger botnet has infected more than 4,300 D-Link routers, specifically the DIR-850L and DIR-818LW models, which are no longer supported by the manufacturer. This malware, identified by researchers at Qianxin's XLab, converts compromised devices into reconnaissance tools that can perform scanning and proxying activities. It exploits vulnerabilities including CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837. The majority of infections are reported in South Korea, followed by China and other countries. AryStinger's design allows attackers to efficiently conduct reconnaissance on potential targets, increasing the likelihood of successful intrusions. The botnet's activity began shortly after law enforcement disrupted a previous botnet, AVrecon, which targeted the same router models. Users are advised to replace outdated routers and apply security measures to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 91d ago How this analysis works

Timeline

2016-08-25
CVE-2016-5681 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-07-01
AVrecon botnet documented
Lumen Technologies reported on the AVrecon botnet targeting D-Link routers.
Techtimes
2025-07-11
CVE-2013-3307 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-02
CVE-2025-11837 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-11
Operation Lightning disrupts AVrecon
Law enforcement seized domains and servers linked to AVrecon, targeting the same router models.
Techtimes
2026-03-12
AryStinger activity detected
XLab's telemetry recorded AryStinger infections starting the same day as the FBI FLASH notice.
Techtimes
2026-06-17
Qianxin publishes AryStinger findings
Qianxin XLab released technical details about the AryStinger botnet and its capabilities.
Techtimes

More articles in this cluster (11)

Following this threat?

Track AryStinger, Qnap and CVE-2013-3307 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed