Infected Routers Become a Hidden Scanning Fabric

The danger is not just that thousands of home routers are infected. They are being used as a distributed layer for scanning, proxying, and traffic relay, which makes attacker reconnaissance look like ordinary residential traffic and makes IP blocking far less effective. Compromised routers can also change DNS settings, so the attacker can redirect browsing without touching passwords. Qianxin XLab says AryStinger is active on more than 4,000 outdated D-Link routers, with most infections tied to DIR-850L and DIR-818LW devices. The malware turns each device into a remote executor for scanning and proxy work, and it can also tamper with DNS and inspect network traffic. The group uses older flaws, including CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837. The forward risk is persistence at scale: once routers are in this state, they become a reusable residential proxy and reconnaissance fabric for later intrusions. That changes both attribution and containment, because the attacker is no longer coming from one source address.

Part of the PlainSec briefing for 2026-06-23

Sources