📰 'AryStinger' Botnet Enslaves Thousands of Outdated D-Link Routers

🤖 New 'AryStinger' botnet hijacks thousands of end-of-life D-Link routers using 13-year-old flaws. The compromised devices are used as a proxy network for attacks. If you own a DIR-850L or DIR-818LW, replace it now! #Botnet #IoT #CyberSecurity

🌐 cyber[.]netsecops[.]io

🔗 https://cyber.netsecops.io/articles/arystinger-botnet-hijacks-end-of-life-d-link-routers/?utm_source=mastodon&utm_medium=social&utm_campaign=daily

AryStinger: la botnet che trasforma router D-Link in armi silenziose per attacchi globali

AryStinger è una nuova botnet scoperta da XLab che ha compromesso oltre 4.000 router D-Link obsoleti trasformandoli in proxy per attacchi di ricognizione e intrusione globali. Sfrutta vulnerabilità vecchie di anni e comunica via Protobuf cifrato con XOR — un'infrastruttura invisibile per APT e cybercriminali.

https://insicurezzadigitale.com/arystinger-la-botnet-che-trasforma-router-d-link-in-armi-silenziose-per-attacchi-globali/

AryStinger botnet infected thousands of D-Link routers worldwide

A previously undocumented malware botnet named AryStinger has compromised more than 4,000 outdated routers to turn them into proxies for malicious traffic.

BleepingComputer

"Popa ist darauf ausgelegt, Geräte zu einem privaten Proxy-Netzwerk zusammenzuschalten (entweder mit oder ohne informierte Zustimmung des Gerätebesitzers). Geräte, die Teil des Popa-Botnetzes sind, dienen als Relais- oder Ausgangsknoten, um Dritten zu ermöglichen, ihren Datenverkehr über eine scheinbar normale private Internetverbindung zu leiten."

https://borncity.com/blog/2026/06/22/popa-botnetz-kapert-smart-tvs-fuer-web-scraping/

https://www.qurium.org/forensics/finding-popa/

#cybersecurity #SmartTV #botnet

Popa Botnetz kapert Smart TVs für Web-Scraping

Sicherheitsforscher haben ein Botnetz enttarnt, welches Millionen Smart TVs gekapert hat. Die Millionen Android Smart TV-Geräte, die Teil des Popa-Botnets sind, leiteten Webverkehr (Web-Scaping) an…

Borns IT- und Windows-Blog

AryStinger Malware Infects 4,300 Routers in Global Reconnaissance Network

Meet AryStinger, a sneaky new malware that's hijacked over 4,300 home routers worldwide, transforming them into a covert network for spying and proxying - and the numbers are still climbing. This cunning malware lets hackers scan the internet, tunnel traffic, and run secret commands, all while hiding their…

https://osintsights.com/arystinger-malware-infects-4300-routers-in-global-reconnaissance-network?utm_source=mastodon&utm_medium=social

#ArystingerMalware #EmergingThreats #MalwareOperations #ReconnaissanceNetwork #Botnet

AryStinger Malware Infects 4,300 Routers in Global Reconnaissance Network

Learn how AryStinger malware infects 4,300 routers, turning them into a global reconnaissance network, and take steps to protect your devices now.

OSINTSights

I’ve been running honeypots on the internet for about four months. I’ve looked in detail at the mdrfckr botnet (Outlaw) and written a blog post about it.

https://nheinz.dev/blog/2026/06/mdrfckr---a-almost-decade-old-botnet/

#honeypot #botnet #cybersecurity #threathunting #threatintel

MDRFCKR - a (almost) decade old botnet - Niclas Heinz

Personal Website of Niclas Heinz

Le botnet AryStinger cible des milliers de routeurs D-Link dans le monde. Les routeurs en fin de vie sont une surface d'attaque persistante : firmware non mis à jour, identifiants par défaut, exposition directe sur internet. Le problème n'est pas nouveau — mais les appareils restent en prod longtemps après la fin du support constructeur. #infosec #botnet #IoT
https://www.bleepingcomputer.com/news/security/arystinger-botnet-infected-thousands-of-d-link-routers-worldwide/
AryStinger botnet infected thousands of D-Link routers worldwide

A previously undocumented malware botnet named AryStinger has compromised more than 4,000 outdated routers to turn them into proxies for malicious traffic.

BleepingComputer

A rede de malware AryStinger comprometeu mais de quatro mil routers antigos para desviar tráfego de internet. A ameaça silenciosa foi detectada pela equipa de segurança XLab e utiliza os equipamentos como intermediários de tráfego ilícito.

🔗 https://tugatech.com.pt/t85903-botnet-arystinger-infeta-milhares-de-routers-antigos-para-desviar-trafego-de-internet

#botnet #internet 

Botnet AryStinger infeta milhares de routers antigos para desviar tráfego de internet

Uma nova ameaça silenciosa está a atingir equipamentos de rede desatualizados em todo o mundo. A rede de malware conhecida como AryStinger já comprometeu mais d

TugaTech

AryStinger Botnet Exploits Flaws in Thousands of D-Link Routers

Meet AryStinger, a sneaky botnet that's hijacked over 4,000 outdated D-Link routers worldwide, turning them into a powerful tool for hackers to carry out stealthy scans and attacks. This malware mastermind breaks down massive tasks into tiny chunks, distributing them across its zombie network for lightning-fast execution.

https://osintsights.com/arystinger-botnet-exploits-flaws-in-thousands-of-d-link-routers?utm_source=mastodon&utm_medium=social

#Arystinger #Botnet #DlinkRouters #IotExploits #MalwareOperations

AryStinger Botnet Exploits Flaws in Thousands of D-Link Routers

Learn how AryStinger botnet exploits D-Link routers, infecting 4,000+ devices. Discover the threat and protect your network now with expert insights.

OSINTSights
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm – Krebs on Security