UNCOS

Thousands of Asus routers are being hit with stealthy, persistent backdoors

Thousands of Asus routers are being hit with stealthy, persistent backdoors

image via Ars Technica

May 28, 2025, 10:12 PM

  • Thousands of Asus routers are infected with a stealthy backdoor.
  • The backdoor survives reboots and firmware updates.
  • Attackers gain access by exploiting vulnerabilities, installing an SSH key for administrative control.
  • Users can check SSH settings and logs to detect infection and remove the backdoor.
  • The threat actor is believed to be amassing compromised devices for future use.

Researchers have discovered a stealthy backdoor infecting thousands of Asus routers, allowing attackers to gain full administrative control. The backdoor persists through reboots and firmware updates, indicating a sophisticated threat. Attackers exploit vulnerabilities, including CVE-2023-39780, to install an SSH key, granting unauthorized access. Users can check their router's SSH settings and logs to determine if they are affected and should remove the key and port setting if needed. The threat actor is believed to be accumulating compromised devices for future use, possibly with nation-state backing.

Read original article

Entities Mentioned

GreyNoiseSekoiaCensys

Topics Covered

Biz & ITSecurityasus routersbackdoorshacking

Comments (0)

No comments yet.