institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published loading...Updated

Thousands of Asus routers compromised by "ViciousTrap" backdoor

  • GreyNoise, a threat monitoring company, discovered in March 2025 a botnet called AyySSHush compromising over 9,000 Asus routers globally.
  • The botnet exploits old authentication bypass bugs and a critical command injection flaw CVE-2023-39780 to gain persistent backdoor access.
  • Attackers disable Trend Micro's AiProtection, turn off logging, enable SSH on port 53282, and add attacker-controlled keys, maintaining access across reboots and updates.
  • GreyNoise noted the stealthy campaign uses official Asus features for persistence and advised users to check SSH settings and apply firmware updates promptly.
  • The operation likely involves well-resourced actors, possibly nation-state linked, and suggests groundwork for a future botnet, though exact goals remain unclear.
Insights by Ground AI
Does this summary seem wrong?

43 Articles

All
Left
Center
6
Right
3
Right

It's not enough to update their software, you need to reset them.

·Budapest, Hungary
Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 67% of the sources are Center
67% Center
Factuality

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news in on Wednesday, May 28, 2025.
Sources are mostly out of (0)