AryStinger botnet infected thousands of D-Link routers worldwide
2026-06-22T01:23:33Z•889e4a9ee4f5d7fa6178d1fba73262bd2e062d162943e35abe839e6b77134d5c
AryStingerBlueNoroffD-LinkGravity SMTPIcarusKlueMastra AINorth KoreaOAuthPIIPrinz EugenSapphire SleetTexas Parks and WildlifeWordPressbotnetdata breachdriver licenses','personal-datainfo-disclosureno-ransom-notenpmpluginproxyransomwarerouterssupply-chain
What happened
Multiple high-impact security incidents and active exploits were reported: a new AryStinger botnet has infected over 4,000 outdated D-Link routers and turned them into proxy nodes; a new 'Prinz Eugen' ransomware family prioritizes recently modified files and leaves no ransom note; Microsoft attributes a Mastra AI npm supply‑chain compromise (140+ packages) to North Korean group Sapphire Sleet/BlueNoroff; Klue suffered an OAuth breach with stolen tokens and an extortion claim by the Icarus group; an unauthenticated information‑disclosure flaw in the Gravity SMTP WordPress plugin is being abused
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 889e4a9ee4f5d7fa6178d1fba73262bd2e062d162943e35abe839e6b77134d5c
- Enrichment time
- 2026-06-22T01:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.