Security Briefing | June 22, 2026 - New AryStinger Botnet Infects 4,300+ Legacy Routers for Reconnaissance
A new malware family called AryStinger has compromised over 4,300 outdated D-Link routers, building them into a distributed proxy network used for reconnaissance rather than traditional DDoS attacks. The infection count is still rising.
By EACA Summit Content Team

1. AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
A new malware family, AryStinger, has compromised over 4,300 outdated D-Link routers, turning them into a distributed proxy network for reconnaissance. Unlike typical DDoS botnets, AryStinger is used for pre-attack intelligence gathering. The infection count is still rising.
Verified Facts
- AryStinger malware has infected at least 4,300 legacy routers
- The malware turns routers into proxies for malicious traffic, not DDoS
- QiAnXin's XLab identified and named the malware
Evidence
- QiAnXin XLab report
- BleepingComputer article
- The Hacker News article
Impact Defenders should inventory and patch or replace legacy routers, as they are being repurposed for stealthy reconnaissance that can precede targeted attacks.
Confidence Level: High
The Hacker News | BleepingComputer
Also Noted
Additional reporting on the Mastra NPM supply chain attack (previously covered June 17 and June 21) suggests the malicious dependency was designed to target cryptocurrency browser extensions specifically, though this detail carries Medium confidence pending further confirmation. A previously reported proof-of-concept exploit for Apple's boot defenses (covered June 20) continues to circulate with no patch available.
All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.



