• News/
  • https://www.bleepingcomputer.com/news/security/botnet-hacks-9-000-plus-asus-routers-to-add-persistent-ssh-backdoor/

Botnet hacks 9,000+ ASUS routers to add persistent SSH backdoor

BleepingComputer
·
Bill Toulas
·
Published May 28, 2025
·
Updated

Over 9,000 ASUS routers are compromised by a novel botnet dubbed "AyySSHush" that was also observed targeting SOHO routers from Cisco, D-Link, and Linksys. The campaign was discovered by GreyNoise security researchers in mid-March 2025, who reports that it carries the hallmarks of a nation-state threat actor, though no concrete attributions were made. The threat monitoring firm reports that the attacks combine brute-forcing login credentials, bypassing authentication, and exploiting older vulnerabilities to compromise ASUS routers, including the RT-AC3100, RT-AC3200, and RT-AX55 models. Specifically, the attackers exploit an old command injection flaw tracked as CVE-2023-39780 to add their own SSH public key and enable the SSH daemon to listen on the non-standard TCP port 53282. This modifications allow the threat actors to retain backdoor access to the device even between reboots and firmware updates. "Because this key is added using the official ASUS features, this config change is persisted across firmware upgrades," explains another related report by GreyNoise. "If you've been exploited previously, upgrading your firmware will NOT remove the SSH backdoor." The attack is particularly stealthy, involving no malware, while the attackers also turn off logging and Trend Micro's AiProtection to evade detection. Characteristically, GreyNoise reports logging just 30 malicious requests associated with this campaign over the past three months, though 9,000 ASUS routers have been i...

Read full article

Affected Software

6 affected components
Cisco SOHO routers
D-Link SOHO routers
LinkSys SOHO routers
ASUS RT-AC3100
ASUS RT-AC3200
ASUS RT-AX55
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What recent security incident is highlighted in the article?

The article discusses a botnet called 'AyySSHush' that compromised over 9,000 ASUS routers to install a persistent SSH backdoor.

2

Which brands of routers were targeted by the botnet?

The botnet targeted ASUS routers and also attempted to compromise SOHO routers from Cisco, D-Link, and Linksys.

3

What specific ASUS router models were mentioned as affected?

The affected ASUS router models mentioned include the RT-AC3100, RT-AC3200, and RT-AX55.

4

What type of vulnerability does the botnet exploit?

The botnet exploits vulnerabilities in the routers to add a persistent SSH backdoor for unauthorized access.

5

Who discovered this botnet campaign?

The campaign was discovered by GreyNoise security researchers in mid-March 2025.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203