AryStinger botnet infected thousands of D-Link routers worldwide

2026-06-22T13:23:32Z20dfab7d1cf45277952dd312a19156f7947e8c3d5b7fbd6e0f9d1627c93edb70
AryStingerBlueNoroffCISAD-Link routersEDR evasionFortiBleedFortinet credentials leakGentlemen ransomwareGravity SMTPIcarusKlueMastra AIOAuth token theftPrinz EugenSapphire SleetSplunk EnterpriseTexas Parks and Wildlife data breachUSB worm','crypto-stealer','MFA bypass','AI agents identityWordPress vulnerabilityactive exploitationbotnetdrivers licenses exposednpm compromiseransomwaresupply chain

What happened

Multiple high-impact security incidents reported: a new AryStinger botnet has compromised ~4,000 outdated D-Link routers to proxy malicious traffic; a Prinz Eugen ransomware strain prioritizes recently modified files and leaves no ransom note; Microsoft attributes a Mastra AI npm supply-chain compromise to North Korea’s Sapphire Sleet (BlueNoroff) affecting 140+ packages; Klue confirmed an OAuth-token theft with the Icarus extortion group claiming the attack; an unauthenticated info-disclosure bug in the Gravity SMTP WordPress plugin is being actively exploited on ~100k sites; CISA warned of a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
20dfab7d1cf45277952dd312a19156f7947e8c3d5b7fbd6e0f9d1627c93edb70
Enrichment time
2026-06-22T13:23:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · AryStinger botnet infected thousands of D-Link routers worldwide · Baitaphish