logo

New Botnet Plants Persistent Backdoors in ASUS Routers

ID: b9326ef2-25da-51a8-8fd4-9568415d0c1e

STIX ID: report--b9326ef2-25da-51a8-8fd4-9568415d0c1e

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-05-29

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Researchers uncovered AyySSHush, a router-focused botnet that compromises ASUS devices via brute force and a high-severity command-injection flaw (CVE-2023-39780), undermines built-in security, and implants persistent SSH backdoors in NVRAM so infections survive reboots and firmware updates; the campaign likely enrolled thousands of routers into a larger ORB relay network (≈12,000 peak, ≈4,500 remaining) and is assessed as likely Chinese-linked (ViciousTrap).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.