Just in:
Russia brings cryptocurrency market law into force // Drone strike damages Kuwait residential complex, no injuries // Haldwani purification row: Caste back on political centre-stage // TotalEnergies, ExxonMobil connect Angolan suppliers to procurement // Hong Kong Ranks Fifth Among APAC’s Preferred Living Investment Destinations as 85% of Investors Plan to Increase Sector Investment // Xi reaches Cairo as China broadens Egypt engagement // Midea to Showcase SpaceMaster Series with Graphene Technology at IFA 2026 // Norway weighs tighter controls on camera smart glasses // InnoHK R&D Centres Establish Base at Science Park to Drive Emerging Industries and Pioneer Future Innovation // Macao Economic, Trade, and Tourism Investment Promotion Seminar Convened in Jakarta, Indonesia, Fostering Multi-Dimensional Cooperation to Jointly Explore New Opportunities Along the Silk Road // Anthropic broadens Claude access with Fable 5.1 // Delhi tops SIR deletion in percentage, Maharashtra in absolute numbers // Macao Economic, Trade and Tourism Investment Promotion Seminar Held in Singapore, Deepening Multi-Domain Cooperation to Empower Regional Growth // Gambling Goblin repurposes Brazil government sites for SEO // Inovatif Media Asia Sets Regional Ambitions in Motion with Tun Ahmad Fuzi as Strategic Advisor // GCC workplace AI adoption reaches 93% // Wellcome Partners with CJ Foods to Bring Over 100 Korean Favourites to Hong Kong // UAE non-oil growth accelerates to 20-month high // UAE presses ahead with projects despite uncertainty // Apple raises evidence-destruction claims against OpenAI //

Legacy routers fuel AryStinger scanning network

A new botnet campaign has compromised more than 4,300 ageing routers, turning mainly unsupported D-Link devices into a distributed network for scanning, proxying and preparing future cyber intrusions.

The malware, named AryStinger by threat researchers, has been observed targeting routers built around RTL819X-series chipsets, a generation widely used in consumer and small-office networking equipment from roughly 2012 to 2015. The affected devices are led by D-Link DIR-850L and DIR-818LW models, both of which have passed their service life and no longer receive firmware fixes.

The campaign marks a shift from the more familiar use of infected routers for crude distributed denial-of-service attacks. AryStinger appears designed as reconnaissance infrastructure, allowing operators to split large scanning jobs across thousands of compromised devices. Each infected router can act as an “executor”, probing domains, testing services, forwarding traffic and helping attackers disguise their true location before deeper intrusions are attempted.

The known infection count covers RTL819X-class routers only. A second version of the malware, written in Go and aimed at network-attached storage devices, has also been identified, but its scale remains unclear. That leaves open the possibility that the real footprint of the operation is larger than the router count now visible through exposed backdoor behaviour.

DIR-850L devices account for the largest share of identified infections, followed by DIR-818LW units. Other affected models include DIR-816L, DIR-818L, DWR-118 and DIR-817LW. Geographically, the detected router infections are concentrated in South Korea and China, with smaller clusters in Sweden, Malaysia and Singapore. The distribution reflects where unsupported devices remain online rather than where the operators are based.

AryStinger gains persistence by deploying Dropbear, a lightweight SSH server, on compromised routers. It then opens access through firewall changes, allowing the attacker to maintain remote login capability. The malware communicates with command-and-control servers using HTTP or HTTPS, with traffic encoded through Protobuf and protected by simple XOR encryption. Once enrolled, each device receives an identifier and waits for tasks.

Those tasks can include IP scanning, DNS scanning, HTTP availability checks, tunnel forwarding, command execution and payload delivery. The Go-based version is broader, adding tools used for service discovery, subdomain enumeration and web probing. The router-focused version is leaner, reflecting the limited processing power of older embedded hardware.

The malware has been seen exploiting long-known vulnerabilities, including CVE-2013-3307 and CVE-2016-5681, as well as CVE-2025-11837 in the NAS-focused variant. The reliance on old flaws highlights the enduring risk posed by abandoned hardware that remains connected long after official support ends. Some of the targeted products have been outside normal firmware maintenance for years.

D-Link’s lifecycle notices for many of the affected DIR-series devices state that end-of-life and end-of-service products no longer receive technical support, firmware updates or security remediation. Users are advised to retire and replace them, rather than expect patches for newly disclosed exploitation paths. That position leaves households and small businesses exposed if they continue using older units at the edge of their networks.

The threat is not limited to the owner of the infected router. A compromised device can become a staging point for attacks against third parties, making traffic appear to originate from a residential or small-office connection. It can also be used to inspect local network activity, alter DNS settings, redirect users to phishing or malware sites, and support lateral movement against other devices behind the same gateway.

The campaign also shows why attackers value routers as durable footholds. They are always on, often poorly monitored and rarely replaced unless they fail. Many users never log into router administration panels after installation, leaving default settings, exposed services and old firmware in place for years. Security tools installed on computers and phones may not detect malicious code running on the gateway itself.

AryStinger’s hardcoded communication key contains a “2024” string, but there is no confirmed evidence that the campaign began that year. What is clearer is that the operators have maintained and updated multiple malware builds, including dozens of router samples and more than 20 Go-based variants observed since April.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Midea to Showcase SpaceMaster Series with Graphene Technology at IFA 2026 // UAE non-oil growth accelerates to 20-month high // Tenchijin Joins “Science Castle Asia 2026” as Official Main Partner to Inspire Asia’s Next Generation of Researchers // Amicura X1 Max Smart Cat Litter Box:AliExpress France Official Warehouse, Litter Box at One Click // Wellcome Partners with CJ Foods to Bring Over 100 Korean Favourites to Hong Kong // METR attackers drain $600,000 in AI credits // Norway weighs tighter controls on camera smart glasses // Macao Economic, Trade, and Tourism Investment Promotion Seminar Convened in Jakarta, Indonesia, Fostering Multi-Dimensional Cooperation to Jointly Explore New Opportunities Along the Silk Road // Single-word dispute leaves G20 finance statement divided // Apple raises evidence-destruction claims against OpenAI // LatAm gushers and possible Venezuela exit a nightmare for Opec // Russia brings cryptocurrency market law into force // Macao Economic, Trade and Tourism Investment Promotion Seminar Held in Singapore, Deepening Multi-Domain Cooperation to Empower Regional Growth // Inovatif Media Asia Sets Regional Ambitions in Motion with Tun Ahmad Fuzi as Strategic Advisor // Hong Kong Ranks Fifth Among APAC’s Preferred Living Investment Destinations as 85% of Investors Plan to Increase Sector Investment // The Mineral Boutique Limited Welcomes CCS Clarification and Reaffirms Asia Growth Strategy // Xi reaches Cairo as China broadens Egypt engagement // Haldwani purification row: Caste back on political centre-stage // Putin holds talks with Pezeshkian in Bishkek // TotalEnergies, ExxonMobil connect Angolan suppliers to procurement //