إبراهيم بوحيمد | Ibrahim Buhaimed[verified]@buhaimediGeneral
The post identifies targeted D-Link router models and references three CVEs but offers no further exploitation, patch, or technical details.
Elusive[verified]@ElusivePrivacyActive Exploitation
AryStinger leverages several CVEs to compromise end‑of‑life D‑Link routers, turning them into active proxy and scanning devices. No patches exist, so the only mitigative action is hardware replacement.
connect24h[verified]@connect24hExploit
The post reports that older D‑Link routers are vulnerable to multiple CVEs and can be targeted using the AryStinger tool, which performs scanning, tunneling, and DNS hijacking, but it offers no patch guidance or in-the-wild evidence.
DFIR Radar[verified]@DFIR_RadarExploit
The post reports an actively exploited botnet that leverages multiple legacy CVEs and includes functional exploit binaries, with a vendor patch already released.
CyberAlertsHQ[verified]@CyberAlertsHQActive Exploitation
AryStinger is actively exploiting multiple end‑of‑life vulnerabilities (CVE‑2013‑3307, CVE‑2016‑5681, CVE‑2025‑11837) in D‑Link routers, compromising thousands of devices that are now co‑opted into a botnet used for scanning, tunneling, and command execution.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
The analysis confirms that AryStinger malware actively exploited CVE‑2013‑3307 and CVE‑2016‑5681 to compromise thousands of legacy routers, turning them into a reconnaissance network.
كاسبر سكاي@KasperskyDevActive Exploitation
Malware AryStinger exploited CVE-2013-3307 and CVE-2016-5681 to compromise over 4,300 D-Link routers worldwide, converting them into scanning and proxy resources for further attacks.
Meridian Group@MeridianEUActive Exploitation
AryStinger botnet leveraged CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837 to infect thousands of legacy D‑Link routers and NAS devices, using them as proxy infrastructure for illicit activity.