ZeroHour
Security Affairspublished ()ingested @securityaffairs

New AyySSHush botnet compromised over 9,000 ASUS routers, adding a persistent SSH backdoor.

highMalwareimportance 47CVE-2023-39780

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-39780
Authenticated OS Command Injection in ASUS RT-AX55 Routers

ASUS RT-AX55 routers contain an OS command injection vulnerability (CWE-78) that allows a remote, authenticated attacker to execute arbitrary operating-system commands on the device. The flaw is triggered when an authenticated session submits crafted input that the router passes to its underlying OS without proper sanitization, though the available data does not identify the specific vulnerable parameter or affected firmware versions. Successful exploitation yields arbitrary command execution at the router's privilege level, which an attacker could use to change device configuration, establish persistence, or pivot into the networks behind the router. Any deployed ASUS RT-AX55 router is affected per CISA's listing, with the greatest risk on units whose management interface is reachable remotely. CISA added the issue to the Known Exploited Vulnerabilities catalog on 2025-06-02 (noting it as represented by CVE-2023-41346), confirming exploitation in the wild; EPSS currently estimates a 33.9% probability of exploitation within 30 days (98th percentile), no public PoC is known, and ransomware use is unknown.

Do: Update RT-AX55 firmware to the latest release from ASUS, checking the vendor's security advisory for CVE-2023-39780 and the related CVE-2023-41346, as the available data does not specify a fixed version. Until patched, restrict administrative access (disable WAN-side/remote management if not needed), enforce strong administrator credentials, and review device settings for signs of tampering. Federal agencies should apply vendor mitigations per BOD 22-01 timelines or discontinue use of affected RT-AX55 routers if mitigations are unavailable.

8.840% KEV PoC ×7
  • ASUS RT-AX55 Routers
largehundreds of thousands of units deployed worldwide, with tens of thousands to hundreds of thousands likely internet-exposed (estimate; no RT-AX55-specific…
Full article390 words · extracted from securityaffairs.com · click to collapse

GreyNoise researchers warn of a new AyySSHush botnet compromised over 9,000 ASUS routers, adding a persistent SSH backdoor.

GreyNoise discovered the AyySSHush botnet has hacked over 9,000 ASUS routers, adding a persistent SSH backdoor.

“Using an AI powered network traffic analysis tool we built called SIFT, GreyNoise has caught multiple anomalous network payloads with zero-effort that are attempting to disable TrendMicro security features in ASUS routers, then exploit vulnerabilities and novel tradecraft in ASUS AiProtection features on those routers.” states GreyNoise.

The threat intelligence firm uncovered a stealth campaign on March 18, 2025, where attackers gained persistent access to thousands of internet-exposed ASUS routers. Using subtle tactics, like auth bypasses and abuse of legit settings, the attackers avoid detection while keeping control, even after reboots or updates. Though attribution remains unclear, the campaign shows signs of a skilled, well-funded adversary building a covert botnet infrastructure.

“GreyNoise has identified an ongoing exploitation campaign in which attackers have gained unauthorized, persistent access to thousands of ASUS routers exposed to the internet.” reads the report published by GreyNoise. “The attacker’s access survives both reboots and firmware updates, giving them durable control over affected devices.”

The payloads observed by the experts only target ASUS RT-AC3100 or RT-AC3200 with an Out-Of-Box configuration.

GreyNoise also found a payload exploiting the authenticated command injection flaw CVE-2023-39780 in ASUS RT-AX55 v3.0.0.4.386.51598 to execute arbitrary system commands.

The attackers exploit the command injection flaw to add their SSH key and enable access on port 53282, ensuring persistent backdoor access across reboots and updates.

“This payload leverages built-in ASUS router features to enable SSH on both LAN and WAN, bind it to TCP/53282, and add an attacker-controlled public key.” ‍reads the full technical analysis published by GreyNoise.  “Because this key is added using the official ASUS features, this config change is persisted across firmware upgrades. If you’ve been exploited previously, upgrading your firmware will NOT remove the SSH backdoor.”

As of May 27, nearly 9,000 ASUS routers are confirmed compromised, based on Censys data. Despite the scale, only 30 related requests were observed over three months, highlighting how stealthy the campaign is.

GreyNoise published a list of four IP addresses associated with the botnet’s campaign as Indicators of Compromise.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, AyySSHush botnet)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/178413/malware/new-ayysshush-botnet-compromised-over-9000-asus-routers-adding-a-persistent-ssh-backdoor.html