logo

Operation WrtHug, The Global Espionage Campaign Hiding in Your Home Router

ID: 6c1d5d57-81db-57d7-bd15-73e03bdb96f9

STIX ID: report--6c1d5d57-81db-57d7-bd15-73e03bdb96f9

Feed Name: SecurityScorecard Blog

Threat Score
90/100

Date Published: 2025-12-11

Date Updated: 2026-04-29

...
...

SecurityScorecard’s STRIKE team reports on “Operation WrtHug,” a large-scale campaign compromising ASUS WRT routers—mainly end-of-life models—via multiple known OS command-injection and authentication vulnerabilities (including CVE-2023-39780 and others) to create a global espionage network of infected devices (over 50,000 observed). A distinctive shared self-signed TLS certificate with a 100-year expiration serves as a tracking IOC; researchers assess low-to-moderate confidence that a China-affiliated actor is conducting an ORB-style operation and advise monitoring legacy devices and applying ASUS mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.