logo

Botnet hacks 9,000+ ASUS routers to add persistent SSH backdoor

ID: c8fd5833-d986-5054-a385-4289353ac2f2

STIX ID: report--c8fd5833-d986-5054-a385-4289353ac2f2

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-05-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

GreyNoise researchers observed a stealthy campaign called "AyySSHush" that has compromised over 9,000 ASUS routers (e.g., RT-AC3100, RT-AC3200, RT-AX55) by brute-forcing credentials and exploiting CVE-2023-39780 to add an SSH key for persistent backdoor access on port 53282; attackers also disable logging and security features to evade detection. The report provides IoCs (four IPs and authorized_keys entries), overlap with other SOHO-focused activity, and recommends firmware updates, checking authorized_keys, and factory resets to remediate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.