AI Stories on SHORT INFO are generated & curated with AI
unverified 23 Jun, 12:09

AryStinger botnet hijacks 4300 end-of-life D-Link routers worldwide proxy network DNS tampering old CVEs

A botnet called AryStinger has hijacked over 4,300 end-of-life D-Link routers worldwide, turning home and small-office devices into proxies that scan networks and run attacker commands. It exploits router flaws as old as 2013. Most infections are in South Korea. Per BleepingCompu

Owners of older D-Link networking gear face a fresh risk. Security researchers have identified a fast-moving botnet called AryStinger that has hijacked more than 4,300 end-of-life D-Link routers, along with some QNAP network-attached storage devices, across the globe. According to BleepingComputer and Malwarebytes, the malware targets long-unsupported models such as the DIR-850L and DIR-818LW and exploits vulnerabilities disclosed as far back as 2013, including CVE-2013-3307. Once a device is compromised, AryStinger converts it into what researchers call an Executor: a remotely controlled node that can scan networks, route traffic as a proxy, open tunnels, and run commands on the attacker's behalf. Researchers warn that the malware can also tamper with a router's DNS settings, allowing operators to silently redirect a victim's web traffic toward phishing pages or sites that host malware. The infections are concentrated in South Korea, which accounts for nearly half of compromised devices, followed by China, with smaller clusters in Sweden, Malaysia, and Singapore. Because the affected hardware no longer receives security updates, researchers recommend replacing end-of-life routers rather than relying on patches.

#cyber
Published on
XThreadsFacebookBluesky