Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Vulnerabilities

AryStinger botnet hijacks 4,000 D-Link routers globally

A newly discovered malware campaign has turned thousands of outdated D-Link routers into proxies for malicious traffic.

AryStinger botnet hijacks 4,000 D-Link routers globally
Tima Miroshnichenko · Pexels

A previously unknown malware operation, dubbed AryStinger, has compromised over 4,000 end-of-life D-Link routers worldwide, repurposing them as proxies for cybercriminal activities. The botnet, uncovered by Qianxin’s XLab threat intelligence team, leverages outdated firmware vulnerabilities to execute distributed scanning, command execution, and network traffic interception on behalf of attackers. Its modular design allows threat actors to split large-scale reconnaissance tasks across infected devices, accelerating the early stages of intrusion campaigns.

The malware primarily targets two D-Link models: the DIR-850L and DIR-818LW, both of which were previously exploited by the AVrecon botnet in 2023. AryStinger’s infrastructure enables attackers to distribute scanning workloads across compromised routers, reducing detection risks while improving the efficiency of footprinting operations. Beyond scanning, the malware can alter DNS settings, hijack user browsing sessions, and monitor all inbound and outbound traffic, posing significant risks to both home and small business networks.

Geographic spread and technical variants

XLab’s telemetry data reveals that nearly half of all infections are concentrated in South Korea (48.5%), followed by China (31.8%), Sweden (6.4%), Malaysia (3.5%), and Singapore (2.5%). The botnet exists in two distinct variants: a C-based version focused on routers and a more advanced Go-based variant targeting network-attached storage (NAS) systems. While the NAS variant remains less widespread, it incorporates open-source penetration testing tools for internal network reconnaissance, command execution, and payload delivery in multiple programming languages, including Go, Java, and Python.

Key facts
  • 4,000+ D-Link routers infected globally
  • Primary targets: DIR-850L and DIR-818LW models
  • Top infection regions: South Korea (48.5%), China (31.8%)
  • Exploited vulnerabilities: CVE-2013-3307, CVE-2016-5681, CVE-2025-11837
  • Malware variants: C-based (routers), Go-based (NAS systems)

Risks and mitigation

The distributed nature of AryStinger’s scanning infrastructure raises concerns about its potential use in large-scale DNS query floods, though XLab has not observed such attacks to date. The NAS variant’s ability to execute arbitrary code—including shell commands and interpreted scripts—further complicates detection, as it relies on language runtimes that may already exist on compromised hosts. However, the compilation process introduces operational noise, which could aid defenders in identifying malicious activity.

XLab researchers have not attributed AryStinger to any known threat actor, leaving its origins and long-term objectives unclear. For affected users, the recommended course of action is to replace end-of-life routers with supported models or, at minimum, apply the latest available firmware updates. Additional precautions include changing default administrator passwords and disabling remote management interfaces to reduce exposure to future exploits.

For professionals

For professionals: Network operators should monitor for unusual DNS query patterns and outbound traffic from consumer-grade routers, particularly those running outdated firmware. Security teams may prioritize vulnerability scans for the three CVEs exploited by AryStinger, as these flaws remain unpatched on many legacy devices still in service.

What to watch

The emergence of AryStinger highlights the persistent risks posed by unmanaged network devices, particularly in regions with high concentrations of outdated hardware. If the botnet’s operators expand its capabilities to include DNS amplification or other volumetric attacks, the impact could extend beyond individual infections to broader internet infrastructure. Defenders should track updates from XLab and other threat intelligence providers for signs of evolving tactics or new target vectors.

Companies mentioned

D-Link Lumen Technologies Qianxin

Discussion · coming soon

Be the first to join the thread when community discussion launches.