Vulnerabilities & Exploits · IoT / OT Attack

Infected Routers Become a Hidden Scanning Fabric

The danger is not just that thousands of home routers are infected. They are being used as a distributed layer for scanning, proxying, and traffic relay, which makes attacker reconnaissance look like ordinary residential traffic and makes IP blocking far less effective. Compromised routers can also change DNS settings, so the attacker can redirect browsing without touching passwords.

Qianxin XLab says AryStinger is active on more than 4,000 outdated D-Link routers, with most infections tied to DIR-850L and DIR-818LW devices. The malware turns each device into a remote executor for scanning and proxy work, and it can also tamper with DNS and inspect network traffic. The group uses older flaws, including CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837.

The forward risk is persistence at scale: once routers are in this state, they become a reusable residential proxy and reconnaissance fabric for later intrusions. That changes both attribution and containment, because the attacker is no longer coming from one source address.

2 sources · Jun 22

CVE-2013-3307

NVD KEV

CVSS 8.3 HIGH: linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command… EPSS 56% (99th percentile).

CVE-2016-5681

NVD KEV

CVSS 9.8 CRITICAL: stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx… EPSS 12% (96th percentile).

CVE-2025-11837

NVD KEV

CVSS 9.8 CRITICAL: an improper control of generation of code vulnerability has been reported to affect Malware Remover. EPSS 1% (72nd percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-06-21

Every edition of this story: Infected Routers Become a Hidden Scanning Fabric

More from today