Thousands of Asus routers are being hit with stealthy, persistent backdoors
image via Ars Technica
May 28, 2025, 10:12 PM
- •Thousands of Asus routers are infected with a stealthy backdoor.
- •The backdoor survives reboots and firmware updates.
- •Attackers gain access by exploiting vulnerabilities, installing an SSH key for administrative control.
- •Users can check SSH settings and logs to detect infection and remove the backdoor.
- •The threat actor is believed to be amassing compromised devices for future use.
Researchers have discovered a stealthy backdoor infecting thousands of Asus routers, allowing attackers to gain full administrative control. The backdoor persists through reboots and firmware updates, indicating a sophisticated threat. Attackers exploit vulnerabilities, including CVE-2023-39780, to install an SSH key, granting unauthorized access. Users can check their router's SSH settings and logs to determine if they are affected and should remove the key and port setting if needed. The threat actor is believed to be accumulating compromised devices for future use, possibly with nation-state backing.
Entities Mentioned
GreyNoiseSekoiaCensys
Topics Covered
Biz & ITSecurityasus routersbackdoorshacking
Comments (0)
No comments yet.