A newly discovered botnet called AryStinger has compromised over 4,000 end-of-life D-Link routers (DIR-850L and DIR-818LW models), exploiting older CVEs including CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837. Infected devices are turned into distributed 'executors' capable of scanning, proxying, tunneling, DNS hijacking, and traffic interception. Researchers at Qianxin's XLab identified two variants: a C-based version targeting routers and a more advanced Go-based version targeting NAS systems with additional reconnaissance capabilities. Nearly half of infections are in South Korea. No threat actor attribution has been made. Owners of EoL routers are advised to replace devices, update firmware, change default credentials, and disable remote management.