logo

AyySSHush: Tradecraft of an emergent ASUS botnet

ID: 5666b643-e82c-539c-902e-490e9aea470b

STIX ID: report--5666b643-e82c-539c-902e-490e9aea470b

Feed Name: GreyNoise Labs

Threat Score
80/100

Date Published: 2025-05-28

Date Updated: 2026-04-27

Author: remy

...
...

GreyNoise’s SIFT detected an active campaign exploiting ASUS router firmware (including CVE-2023-39780) to inject commands that create /tmp/BWSQL_LOG (enabling BWDPI logging) and to enable SSH on TCP/53282 with an attacker-controlled public key that persists across firmware upgrades; the report provides exploit payloads, firmware analysis, proof-of-concept access, and IoCs (several source IPs and the attacker RSA public key) confirming widespread backdooring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.