Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

GreyNoise Flags 9,000 ASUS Routers Backdoored Via Patched Vulnerability

Posted on May 29, 2025May 29, 2025 By CWS

Risk intelligence agency GreyNoise on Wednesday lifted the lid on a stealth malware marketing campaign that has quietly transformed 1000’s of internet-facing ASUS residence and small-office routers into backdoor nodes since no less than mid-March. 

In an advisory coordinated with authorities and business companions, the Washington-based GreyNoise stated unidentified attackers are chaining a mixture of brute-force logins, two older authentication bypass flaws and a 2023 command-injection bug to grab full management of the units, then utilizing official configuration settings to lock in that entry. 

The result’s what GreyNoise calls ‘AyySSHush’, a community of routers that may survive firmware upgrades, manufacturing unit reboots and most anti-malware scans, preferrred actual property for a future botnet or relay infrastructure for skilled hacking groups.

Utilizing scan knowledge from Censys, GreyNoise estimates about 9,000 ASUS routers are confirmed compromised.

Individually, French safety analysis agency Sekoia warned {that a} Chinese language-speaking risk actor referred to as ‘ViciousTrap’ has compromised greater than 5,500 edge units, turning them into honeypots.

Sekoia stated greater than 50 manufacturers, together with SOHO routers, SSL VPNs, DVRs, and BMC controllers, are being monitored by this actor, presumably to gather knowledge on vulnerabilities and exploits affecting these methods.

SecurityWeek sources say the 2 discoveries are linked.

In accordance with GreyNoise, an inner “Sift” anomaly-detection engine flagged three uncommon HTTP POST requests aimed toward absolutely emulated ASUS routers inside the corporate’s sensor grid. Commercial. Scroll to proceed studying.

The corporate’s researchers reconstructed an assault chain that toggles built-in AiProtection capabilities, allows SSH on TCP port 53282, and crops an attacker-controlled public key in non-volatile reminiscence. As a result of the tweak is saved in NVRAM somewhat than on disk, GreyNoise discovered that the backdoor persists even after directors patch the susceptible firmware or power-cycle the router. 

The attackers have been additionally noticed disabling logging to cowl their tracks.

On the centre of the exploitation chain is CVE-2023-39780, a command-injection flaw in a number of ASUS router strains that the seller quietly patched in current firmware photos. GreyNoise says the attackers begin by guessing weak credentials or leveraging two unassigned authentication bypass methods to succeed in an administrative endpoint. The already-patched safety bug is then exploited to run system instructions.

“The techniques used on this marketing campaign (stealthy preliminary entry, use of built-in system options for persistence, and cautious avoidance of detection) are according to these seen in superior, long-term operations,”GreyNoise warned.

“The extent of tradecraft suggests a well-resourced and extremely succesful adversary,” the corporate added. 

Associated: Chinese language UEFI Rootkit Discovered on Gigabyte and Asus Motherboards

Associated: Russia-Linked Cyclops Blink Botnet Attacking ASUS Routers

Associated: Researchers Uncover 40,000-Robust EOL Router, IoT Botnet 

Associated: FBI Disables “Cyclops Blink” Botnet Managed by Russian Intelligence Company

Associated: Chinese language Spies Constructed Huge Botnet of IoT Units to Goal US, Taiwan Navy

Security Week News Tags:ASUS, Backdoored, Flags, GreyNoise, Patched, Routers, Vulnerability

Post navigation

Previous Post: New Windows RAT Evades Detection for Weeks Using Corrupted DOS and PE Headers
Next Post: Cybercriminals Target AI Users with Malware-Loaded Installers Posing as Popular Tools

Related Posts

Salesforce Instances Hacked via Gainsight Integrations Security Week News
Nudge Security Raises $22.5 Million in Series A Funding Security Week News
Oracle E-Business Suite Zero-Day Exploited in Cl0p Attacks Security Week News
SquareX and Perplexity Quarrel Over Alleged Comet Browser Vulnerability Security Week News
Rethinking Success in Security: Why Climbing the Corporate Ladder Isn’t Always the Goal Security Week News
CISA: CVE Program to Focus on Vulnerability Data Quality Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Malicious Document Reader App in Google Play With 50K Downloads Installs Anatsa Malware
  • New GhostFrame Super Stealthy Phishing Kit Attacks Millions of Users Worldwide
  • QuasarRAT Core Functionalities Along with Encrypted Configuration and Obfuscation Techniques Exposed
  • CISO Conversations: Keith McCammon, CSO and Co-founder at Red Canary
  • Resemble AI Raises $13 Million for AI Threat Detection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Malicious Document Reader App in Google Play With 50K Downloads Installs Anatsa Malware
  • New GhostFrame Super Stealthy Phishing Kit Attacks Millions of Users Worldwide
  • QuasarRAT Core Functionalities Along with Encrypted Configuration and Obfuscation Techniques Exposed
  • CISO Conversations: Keith McCammon, CSO and Co-founder at Red Canary
  • Resemble AI Raises $13 Million for AI Threat Detection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark