AryStinger Malware Attacks Routers via CVE-2013-3307
ID: 98f4af90-a812-5168-b91e-09fca8f1b052
STIX ID: report--98f4af90-a812-5168-b91e-09fca8f1b052
Feed Name: securityonline.info
**AryStinger** is a malware campaign that has compromised over 4,300 legacy RTL819X-based routers (notably D-Link DIR-850L and DIR-818LW) and some NAS devices by exploiting known vulnerabilities (CVE-2013-3307, CVE-2016-5681 and a reported CVE-2025-11837); the botnet provides persistent remote access, network scanning and proxying, and can execute source-level payloads (Go/Java/Python), so administrators should replace or update unsupported routers, monitor for suspicious processes (e.g., syswapd0h/syswapd0w) and temporary binaries, and audit network traffic for C2/proxy activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
