216.73.217.22

Thousands of ASUS Routers Hijacked in Stealthy Backdoor Campaign

· Published 29/05/2025 16:10 · Modified 29/05/2025 19:33

Export JSON

Essential information

Published
29/05/2025 16:10
Modified
29/05/2025 19:33
Tags
2025-05-29 CVE-2023-39780 asus routers backdoor botnet operational relay box ssh access
Related entities
7 techniques (mitre)

Description

A sophisticated hacking campaign has compromised approximately 9000 , creating persistent backdoors that survive firmware updates and reboots. The attackers utilize the routers' legitimate features to maintain long-term access without dropping malware or leaving traces. This operation appears to be assembling a distributed network of devices, potentially for a future . The intrusion chain involves brute-force login attempts, exploitation of zero-day vulnerabilities, and the use of . The attackers employ stealthy techniques such as enabling on a custom port, inserting attacker-controlled public keys, and disabling router logging. The campaign's sophistication suggests a formidable and well-funded adversary, possibly associated with Chinese-sponsored hackers.

External references