New Botnet Plants Persistent Backdoors in ASUS Routers
ID: b9326ef2-25da-51a8-8fd4-9568415d0c1e
STIX ID: report--b9326ef2-25da-51a8-8fd4-9568415d0c1e
Feed Name: Dark Reading
Threat Score
Researchers uncovered AyySSHush, a router-focused botnet that compromises ASUS devices via brute force and a high-severity command-injection flaw (CVE-2023-39780), undermines built-in security, and implants persistent SSH backdoors in NVRAM so infections survive reboots and firmware updates; the campaign likely enrolled thousands of routers into a larger ORB relay network (≈12,000 peak, ≈4,500 remaining) and is assessed as likely Chinese-linked (ViciousTrap).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
