Tracking AyySSHush: a Newly Discovered ASUS Router Botnet Campaign
ID: 50e563c4-cdd7-5cad-8ab0-bb9d920c754b
STIX ID: report--50e563c4-cdd7-5cad-8ab0-bb9d920c754b
Feed Name: Censys Blog
**AyySSHush** is a stealthy ASUS router botnet observed in March–May 2025 that abuses legitimate ASUS firmware/configuration features (including AiProtection and BandWidth SQLite logging) and CVE-2023-39780 to install persistent SSH backdoors (bound to TCP/53282) which survive firmware updates and affect thousands of devices worldwide; the report includes prevalence data (4,504 exposed devices as of May 28, 2025), IoCs (malicious SSH public key, /tmp/BWSQL-LOG, authorized_keys locations, several C2 IPs), and detection/mitigation guidance including a Censys query and a live dashboard.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
