AryStinger botnet infected thousands of D-Link routers worldwide

2026-06-22T01:23:33Z889e4a9ee4f5d7fa6178d1fba73262bd2e062d162943e35abe839e6b77134d5c
AryStingerBlueNoroffD-LinkGravity SMTPIcarusKlueMastra AINorth KoreaOAuthPIIPrinz EugenSapphire SleetTexas Parks and WildlifeWordPressbotnetdata breachdriver licenses','personal-datainfo-disclosureno-ransom-notenpmpluginproxyransomwarerouterssupply-chain

What happened

Multiple high-impact security incidents and active exploits were reported: a new AryStinger botnet has infected over 4,000 outdated D-Link routers and turned them into proxy nodes; a new 'Prinz Eugen' ransomware family prioritizes recently modified files and leaves no ransom note; Microsoft attributes a Mastra AI npm supply‑chain compromise (140+ packages) to North Korean group Sapphire Sleet/BlueNoroff; Klue suffered an OAuth breach with stolen tokens and an extortion claim by the Icarus group; an unauthenticated information‑disclosure flaw in the Gravity SMTP WordPress plugin is being abused

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
889e4a9ee4f5d7fa6178d1fba73262bd2e062d162943e35abe839e6b77134d5c
Enrichment time
2026-06-22T01:23:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · AryStinger botnet infected thousands of D-Link routers worldwide · Baitaphish