CVE-2013-3307Active Exploitation

HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

6.0/ 10 priority

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

RISING

Threat summary

  • Active exploitation appears in 8 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days

What's happening

  • Active exploitation reported across 8 signals
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 2d ago at 4 mentions (2026-06-22); latest day: 1
  • 8 total mentions across 5 days

Deep dive

Activity timeline8 mentions / 5d
01234Mentions · 2026-06-18: 1Mentions · 2026-06-21: 1Mentions · 2026-06-22: 4Mentions · 2026-06-29: 1Mentions · 2026-07-06: 1Exploit Tool / Code · 2026-06-22: 1Active Exploitation · 2026-06-18: 1Active Exploitation · 2026-06-21: 1Active Exploitation · 2026-06-22: 4Active Exploitation · 2026-06-29: 1Active Exploitation · 2026-07-06: 1Patch / Workaround · 2026-06-22: 2Technical Details · 2026-06-22: 1Technical Details · 2026-07-06: 106-1806-2106-2206-2907-06
Signal classification1 categories
Active Exploitation
8100.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-181
Active Exploitation1
2026-06-211
Active Exploitation1
2026-06-224
Active Exploitation4
2026-06-291
Active Exploitation1
2026-07-061
Active Exploitation1
Full discourse8 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Active Exploitation

    الاستهداف مركز على راوترات D-Link القديمة: 📍 DIR-850L 📍 DIR-818LW ويستغل ثغرات مثل: 📍 CVE-2013-3307 📍 CVE-2016-5681 📍 CVE-2025-11837

    Post summary

    The post states that attackers target older D-Link routers (DIR-850L, DIR-818LW) by exploiting the CVEs 2013‑3307, 2016‑5681, and 2025‑11837.

    100501.3K
    50.1K followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    AryStinger a new botnet has turned 4,000+ end-of-life D-Link routers (DIR-850L, DIR-818LW) into distributed attack proxies. Exploits: CVE-2013-3307, CVE-2016-5681, CVE-2025-11837. Infected devices scan, proxy, tunnel, hijack DNS, and sniff all traffic. A second Go variant targets NAS, running Shell/Go/Java/Python payloads. 48% of infections sit in South Korea. No attribution to any known cluster. The hardware is EoL no patch is coming. Replace it and kill remote management. Source: @BleepinComputer @VulnerabilityNw

    Post summary

    AryStinger exploits three CVEs to hijack over 4,000 EoL D-Link routers into a botnet acting as attack proxies, with no patch available – replacement is the advised mitigation.

    0101082
    184 followersView on X
  • كاسبر سكاي@KasperskyDev
    Active Exploitation

    برمجية خبيثة سيطرت على أكثر من 4300 راوتر دي لنك وجهاز تخزين شبكي وحوّلتها إلى بروكسيات للمسح وتصفح الغارة البرمجية : AryStinger طريقة الاختراق : Exploiting CVE-2013-3307 and CVE-2016-5681 حجم التأثير : 4300+ routers worldwide #Botnet #DLink #CyberSecurity

    Post summary

    The AriStinger malware has actively exploited CVE‑2013‑3307 and CVE‑2016‑5681 to hijack more than 4,300 D‑Link routers globally, converting them into proxies for scanning and browsing attacks.

    01000234
    40.0K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    AryStinger malware turns 4,300+ end-of-life Realtek RTL819X routers into a distributed reconnaissance botnet, exploiting CVEs from 2013 and 2016 with zero VirusTotal detections at discovery. - Initial access via CVE-2013-3307 and CVE-2016-5681, both over a decade old, spreading a C-based ELF binary from 107.150.106[.]45. The C build persists by dropping Dropbear SSH on port 2332 and communicates via HTTP with Protobuf traffic XOR-encrypted using the hardcoded key sh_#@!_2024_secret, suggesting the op predates the March 12, 2026 detection. - A Go-based second build targets QNAP NAS devices via CVE-2025-11837, patched November 2025 and exploited within five months. It integrates fscan, ksubdomain, httpx, and Tlsx, plus a ScriptWork engine that executes attacker-supplied Go, Java, or Python source directly on device, dropping plaintext payloads to disk. - The fleet operates as an ORB network: each Executor node receives a scan slice, runs it in parallel, and returns results, masking true operator origin. D-Link DIR-850L accounts for ~75% of infected devices. - C2 and download infrastructure uses ajb8[.]com, dataexplore[.]cc, and dataexplore[.]co. Watch for processes named syswapd0h or syswapd0w and unexpected binaries in /tmp/bin. Hunt outbound connections to those three domains, check /tmp/bin, and audit for Dropbear SSH on port 2332. #DFIR_Radar

    Post summary

    AryStinger malware activates multiple old CVEs to convert EOL Realtek routers into a reconnaissance botnet, detailing active exploitation methods, tool usage, and mitigation steps.

    10000253
    1.7K followersView on X
  • CyberAlertsHQ@CyberAlertsHQ
    Active Exploitation

    🚨 NEW: AryStinger — a previously undocumented botnet — has compromised 4,000+ D-Link routers (DIR-850L, DIR-818LW) by exploiting end-of-life vulnerabilities: CVE-2013-3307, CVE-2016-5681, CVE-2025-11837. Infected routers become distributed scanning proxies, tunnels, and command executors for follow-on intrusion operations. The genius: AryStinger splits massive scanning tasks into parallel chunks across compromised routers, covering their tracks in the process. 48.5% of infections are in South Korea, 31.8% China, with secondary clusters in Sweden, Malaysia, Singapore. A Go-based variant also targets NAS systems. The same router models were previously hit by AVrecon. If you own a D-Link DIR-850L or DIR-818LW, assume it’s compromised. Replace it now. Full breakdown 👇 https://www.bleepingcomputer.com/news/security/arystinger-botnet-infected-thousands-of-d-link-routers-worldwide/

    Post summary

    Report details a botnet, AryStinger, that is actively exploiting end-of-life vulnerabilities (CVE‑2013‑3307, CVE‑2016‑5681, CVE‑2025‑11837) to compromise thousands of D‑Link routers worldwide.

    1000092
    85 followersView on X
  • BT Haberler@BTHaberler
    Active Exploitation

    4.000 eski D-Link yönlendirici botnet'e dönüştürüldü: 2013'ten kalma açık hâlâ işe yarıyor! Qianxin XLab araştırmacıları, üretici desteği sona ermiş D-Link DIR-850L ve DIR-818LW modellerini hedef alan AryStinger botnetini keşfetti. Botnet CVE-2013-3307 dahil üç açığı kullanıyor. • Ele geçirilen cihazlar proxy'ye dönüştürülüyor: DNS değiştirme, tarayıcı trafiğini yönlendirme ve ağ trafiğini dinleme yapabiliyor. • Go, Java ve Python kod çalıştırma desteğiyle NAS cihazlarını da hedefleyen ikinci bir varyantı mevcut. • Enfekte cihazların %48,5'i Güney Kore'de; Çin %31,8 ile ikinci sırada. Desteklenmeyen yönlendiriciniz varsa siz de farkında olmadan saldırılara alet oluyorsunuz! #SiberGüvenlik #DLink #Botnet

    Post summary

    The D-Link DIR-850L and DIR-818LW routers are being actively compromised via a botnet that leverages CVE-2013-3307 and two other vulnerabilities, enabling DNS manipulation, traffic hijacking, and remote code execution.

    0000066
    36 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    AryStinger malware exploited decade-old vulnerabilities (CVE-2013-3307, CVE-2016-5681) to compromise 4,300 legacy routers, transforming them into a distributed reconnaissance network. Infected devices scan internal networks and tunnel malicious traffic, complicating attribution. Runtime segmentation could help contain such lateral movement from compromised edge infrastructure. #ThreatIntel :link: Full TRC analysis: https://aviatrix.ai/threat-research-center/arystinger-malware-infects-4300-legacy-routers-2026

    Post summary

    The post confirms that the AryStinger malware actively exploited CVE‑2013‑3307 and CVE‑2016‑5681 to compromise 4,300 legacy routers, underscoring an in‑the‑wild attack scenario.

    0000058
    1.9K followersView on X
  • Meridian Group@MeridianEU
    Active Exploitation

    #AryStinger botnet compromised 4,000+ legacy D-Link routers and NAS devices via CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837. Infected devices used as proxy infrastructure to mask secondary malicious activity. Opportunistic targeting focused on end-of-life hardware. https://t.co/umW9gf0hzS

    Post summary

    The tweet reports that the AryStinger botnet is actively exploiting multiple CVEs to compromise thousands of legacy D-Link routers and NAS devices, using them as a proxy infrastructure for further malicious activity.

    00000130
    60 followersView on X

Explore more