{"id":4271,"date":"2025-05-29T10:03:46","date_gmt":"2025-05-29T10:03:46","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/05\/29\/new-botnet-hijacks-9000-asus-routers-enables-ssh-access-by-injecting-public-key\/"},"modified":"2025-05-29T10:03:46","modified_gmt":"2025-05-29T10:03:46","slug":"new-botnet-hijacks-9000-asus-routers-enables-ssh-access-by-injecting-public-key","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/05\/29\/new-botnet-hijacks-9000-asus-routers-enables-ssh-access-by-injecting-public-key\/","title":{"rendered":"New Botnet Hijacks 9,000 ASUS Routers &amp; Enables SSH Access by Injecting Public Key"},"content":{"rendered":"\n<div>New Botnet Hijacks 9,000 ASUS Routers &#038; Enables SSH Access by Injecting Public Key<\/div>\n<p> \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated botnet campaign dubbed \u201cAyySSHush\u201d has compromised over 9,000 <a href=\"https:\/\/cybersecuritynews.com\/asus-router-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">ASUS routers<\/a> worldwide, establishing persistent backdoor access that survives firmware updates and reboots.\u00a0<\/p>\n<p>The stealthy operation, first detected in March 2025, demonstrates advanced nation-state-level tradecraft by exploiting authentication vulnerabilities and legitimate router features to maintain long-term control without deploying traditional malware.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Attack Chain Exploiting ASUS Routers<\/strong><\/h2>\n<p>The attackers employ a multi-stage exploitation technique that begins with brute-force login attempts against ASUS router interfaces, followed by leveraging two previously undisclosed authentication bypass vulnerabilities.\u00a0<\/p>\n<p>Once privileged access is obtained, the threat actors exploit CVE-2023-39780, an authenticated <a href=\"https:\/\/cybersecuritynews.com\/f5-big-ip-command-injection-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">command injection flaw<\/a> in ASUS router firmware, to execute arbitrary system commands.<\/p>\n<p>The critical payload exploits the oauth_google_refresh_token parameter through a POST request to \/start_apply.htm, injecting the command touch \/tmp\/BWSQL_LOG to enable Bandwidth SQL logging features.\u00a0<\/p>\n<p>This manipulation creates an attack vector through vulnerable functions in the router\u2019s bwsdpi_sqlite binary that pass user-controlled data directly to system() calls.<\/p>\n<p>The attackers then enable SSH access on the non-standard TCP port 53282 and inject their public SSH key (truncated):\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXehW9S5E7IBgg3Nm1-_fVpsrcO2DnbAFeqXJO0X_mbKBDFAU-polO0Z-7iuLfuEqX-rGr8mVN2l3RixmkuPm1fCJIe4HRbcu550MVw6wXau1BqD9oi8qsC1HGuF_kL-5j5YSVVm1g?key=wLUfsK3U--jfonlxgh1EGA\" alt=\"\"><\/figure>\n<\/div>\n<p>This configuration change persists across firmware upgrades because it utilizes official ASUS settings stored in non-volatile memory (NVRAM).<\/p>\n<p>GreyNoise\u2019s <a href=\"https:\/\/www.greynoise.io\/blog\/stealthy-backdoor-campaign-affecting-asus-routers\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">discovery<\/a> was made possible through their AI-powered threat hunting tool called \u201cSift,\u201d which flagged just three anomalous HTTP POST requests among millions of daily internet traffic patterns.\u00a0<\/p>\n<p>The campaign\u2019s stealth is remarkable \u2013 only 30 malicious requests were detected across three months despite compromising thousands of devices.<\/p>\n<p>Sift identified the suspicious activity using advanced machine learning techniques, including custom-built <a href=\"https:\/\/cybersecuritynews.com\/top-10-vulnerabilities-for-large-language-models\/\" target=\"_blank\" rel=\"noreferrer noopener\">Large Language Models (LLMs)<\/a>, nearest neighbor search, and unsupervised clustering to detect payloads targeting ASUS RT-AC3100 and RT-AC3200 routers with factory configurations.\u00a0<\/p>\n<p>Four IP addresses have been identified as indicators of compromise:\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>101.99.91.151<\/li>\n<li>101.99.94.173<\/li>\n<li>79.141.163.179<\/li>\n<li>111.90.146.237<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\"><strong>Immediate Action Required<\/strong><\/h2>\n<p>The campaign represents a significant security threat as the backdoor access cannot be removed through standard firmware updates.\u00a0<\/p>\n<p>ASUS has released patches addressing CVE-2023-39780, but devices compromised prior to patching retain the malicious SSH configuration. The attackers deliberately disable logging and TrendMicro AiProtection features to avoid detection.<\/p>\n<p>Security experts recommend immediately checking ASUS routers for unauthorized SSH services on TCP port 53282 and reviewing authorized_keys files for the attacker\u2019s public key.\u00a0<\/p>\n<p>Organizations should block the identified malicious IP addresses and perform factory resets on suspected compromised devices, followed by complete reconfiguration with strong <a href=\"https:\/\/cybersecuritynews.com\/authentication\/\" target=\"_blank\" rel=\"noreferrer noopener\">authentication<\/a> credentials.\u00a0<\/p>\n<p>The sophistication and persistence of this campaign suggest potential links to <a href=\"https:\/\/cybersecuritynews.com\/how-to-track-advanced-persistent-threats\/\" target=\"_blank\" rel=\"noreferrer noopener\">advanced persistent threat (APT)<\/a> groups utilizing operational relay box (ORB) networks for long-term strategic objectives.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 88%,rgb(169,184,195) 100%)\"><strong>Try in-depth sandbox malware analysis for\u00a0<strong>your SOC tea<\/strong>m. Get\u00a0ANY.RUN special offer only\u00a0until May 31<\/strong>\u00a0-&gt;\u00a0<strong><a href=\"https:\/\/app.any.run\/plans?utm_source=li_csn&amp;utm_medium=article&amp;utm_campaign=telegram_bot&amp;utm_content=plans&amp;utm_term=260525\" target=\"_blank\" rel=\"noreferrer noopener\">Try Here<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-botnet-hijacks-9000-asus-routers\/\">New Botnet Hijacks 9,000 ASUS Routers &amp; Enables SSH Access by Injecting Public Key<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Kaaviya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-botnet-hijacks-9000-asus-routers\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Botnet Hijacks 9,000 ASUS Routers &#038; Enables SSH Access by Injecting Public Key A sophisticated botnet campaign dubbed \u201cAyySSHush\u201d has compromised over 9,000 ASUS routers worldwide, establishing persistent backdoor access that survives firmware updates and reboots.\u00a0 The stealthy operation, first detected in March 2025, demonstrates advanced nation-state-level tradecraft by exploiting authentication vulnerabilities and legitimate [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[660,677,129,63,258],"tags":[130],"class_list":["post-4271","post","type-post","status-publish","format-standard","hentry","category-botnet","category-cyber-attack-article","category-cyber-security","category-cyber-security-news","category-malware","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4271"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4271"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4271\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4271"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4271"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4271"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}