Botnet hacks 9,000+ ASUS routers to add persistent SSH backdoor
ID: c8fd5833-d986-5054-a385-4289353ac2f2
STIX ID: report--c8fd5833-d986-5054-a385-4289353ac2f2
Feed Name: Bleeping Computer
GreyNoise researchers observed a stealthy campaign called "AyySSHush" that has compromised over 9,000 ASUS routers (e.g., RT-AC3100, RT-AC3200, RT-AX55) by brute-forcing credentials and exploiting CVE-2023-39780 to add an SSH key for persistent backdoor access on port 53282; attackers also disable logging and security features to evade detection. The report provides IoCs (four IPs and authorized_keys entries), overlap with other SOHO-focused activity, and recommends firmware updates, checking authorized_keys, and factory resets to remediate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
