logo

Tracking AyySSHush: a Newly Discovered ASUS Router Botnet Campaign

ID: 50e563c4-cdd7-5cad-8ab0-bb9d920c754b

STIX ID: report--50e563c4-cdd7-5cad-8ab0-bb9d920c754b

Feed Name: Censys Blog

Threat Score
78/100

Date Published: 2025-05-30

Date Updated: 2026-04-27

Author: Ivonne Francia; Himaja Motheram

...
...

**AyySSHush** is a stealthy ASUS router botnet observed in March–May 2025 that abuses legitimate ASUS firmware/configuration features (including AiProtection and BandWidth SQLite logging) and CVE-2023-39780 to install persistent SSH backdoors (bound to TCP/53282) which survive firmware updates and affect thousands of devices worldwide; the report includes prevalence data (4,504 exposed devices as of May 28, 2025), IoCs (malicious SSH public key, /tmp/BWSQL-LOG, authorized_keys locations, several C2 IPs), and detection/mitigation guidance including a Censys query and a live dashboard.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.