إبراهيم بوحيمد | Ibrahim Buhaimed[verified]@buhaimediActive Exploitation
The post states that attackers target older D-Link routers (DIR-850L, DIR-818LW) by exploiting the CVEs 2013‑3307, 2016‑5681, and 2025‑11837.
Elusive[verified]@ElusivePrivacyActive Exploitation
AryStinger exploits three CVEs to hijack over 4,000 EoL D-Link routers into a botnet acting as attack proxies, with no patch available – replacement is the advised mitigation.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
AryStinger malware activates multiple old CVEs to convert EOL Realtek routers into a reconnaissance botnet, detailing active exploitation methods, tool usage, and mitigation steps.
CyberAlertsHQ[verified]@CyberAlertsHQActive Exploitation
Report details a botnet, AryStinger, that is actively exploiting end-of-life vulnerabilities (CVE‑2013‑3307, CVE‑2016‑5681, CVE‑2025‑11837) to compromise thousands of D‑Link routers worldwide.
BT Haberler[verified]@BTHaberlerActive Exploitation
The D-Link DIR-850L and DIR-818LW routers are being actively compromised via a botnet that leverages CVE-2013-3307 and two other vulnerabilities, enabling DNS manipulation, traffic hijacking, and remote code execution.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
The post confirms that the AryStinger malware actively exploited CVE‑2013‑3307 and CVE‑2016‑5681 to compromise 4,300 legacy routers, underscoring an in‑the‑wild attack scenario.
كاسبر سكاي@KasperskyDevActive Exploitation
The AriStinger malware has actively exploited CVE‑2013‑3307 and CVE‑2016‑5681 to hijack more than 4,300 D‑Link routers globally, converting them into proxies for scanning and browsing attacks.
Meridian Group@MeridianEUActive Exploitation
The tweet reports that the AryStinger botnet is actively exploiting multiple CVEs to compromise thousands of legacy D-Link routers and NAS devices, using them as a proxy infrastructure for further malicious activity.