AryStinger botnet infected thousands of D-Link routers worldwide
2026-06-22T13:23:32Z•20dfab7d1cf45277952dd312a19156f7947e8c3d5b7fbd6e0f9d1627c93edb70
AryStingerBlueNoroffCISAD-Link routersEDR evasionFortiBleedFortinet credentials leakGentlemen ransomwareGravity SMTPIcarusKlueMastra AIOAuth token theftPrinz EugenSapphire SleetSplunk EnterpriseTexas Parks and Wildlife data breachUSB worm','crypto-stealer','MFA bypass','AI agents identityWordPress vulnerabilityactive exploitationbotnetdrivers licenses exposednpm compromiseransomwaresupply chain
What happened
Multiple high-impact security incidents reported: a new AryStinger botnet has compromised ~4,000 outdated D-Link routers to proxy malicious traffic; a Prinz Eugen ransomware strain prioritizes recently modified files and leaves no ransom note; Microsoft attributes a Mastra AI npm supply-chain compromise to North Korea’s Sapphire Sleet (BlueNoroff) affecting 140+ packages; Klue confirmed an OAuth-token theft with the Icarus extortion group claiming the attack; an unauthenticated info-disclosure bug in the Gravity SMTP WordPress plugin is being actively exploited on ~100k sites; CISA warned of a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 20dfab7d1cf45277952dd312a19156f7947e8c3d5b7fbd6e0f9d1627c93edb70
- Enrichment time
- 2026-06-22T13:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.