Over 9,000 ASUS routers are compromised by a novel botnet dubbed "AyySSHush" that was also observed targeting SOHO routers from Cisco, D-Link, and Linksys. The campaign was discovered by GreyNoise security researchers in mid-March 2025, who reports that it carries the hallmarks of a nation-state threat actor, though no concrete attributions were made. The threat monitoring firm reports that the attacks combine brute-forcing login credentials, bypassing authentication, and exploiting older vulnerabilities to compromise ASUS routers, including the RT-AC3100, RT-AC3200, and RT-AX55 models. Specifically, the attackers exploit an old command injection flaw tracked as CVE-2023-39780 to add their own SSH public key and enable the SSH daemon to listen on the non-standard TCP port 53282. This modifications allow the threat actors to retain backdoor access to the device even between reboots and firmware updates. "Because this key is added using the official ASUS features, this config change is persisted across firmware upgrades," explains another related report by GreyNoise. "If you've been exploited previously, upgrading your firmware will NOT remove the SSH backdoor." The attack is particularly stealthy, involving no malware, while the attackers also turn off logging and Trend Micro's AiProtection to evade detection. Characteristically, GreyNoise reports logging just 30 malicious requests associated with this campaign over the past three months, though 9,000 ASUS routers have been i...
Botnet hacks 9,000+ ASUS routers to add persistent SSH backdoor
BleepingComputer
·Bill Toulas
·Published May 28, 2025
·Updated
Affected Software
6 affected components
Cisco SOHO routers
D-Link SOHO routers
LinkSys SOHO routers
ASUS RT-AC3100
ASUS RT-AC3200
ASUS RT-AX55
Frequently Asked Questions
1
What recent security incident is highlighted in the article?
The article discusses a botnet called 'AyySSHush' that compromised over 9,000 ASUS routers to install a persistent SSH backdoor.
2
Which brands of routers were targeted by the botnet?
The botnet targeted ASUS routers and also attempted to compromise SOHO routers from Cisco, D-Link, and Linksys.
3
What specific ASUS router models were mentioned as affected?
The affected ASUS router models mentioned include the RT-AC3100, RT-AC3200, and RT-AX55.
4
What type of vulnerability does the botnet exploit?
The botnet exploits vulnerabilities in the routers to add a persistent SSH backdoor for unauthorized access.
5
Who discovered this botnet campaign?
The campaign was discovered by GreyNoise security researchers in mid-March 2025.