Global ASUS Router Hack: 9,000 Devices Compromised in Stealthy Cyber Attack

Listen to this Post

Featured Image
A Silent Digital Siege: How Hackers Are Turning ASUS Routers Into Long-Term Assets

A silent but highly effective cyber attack has been sweeping across the globe, targeting ASUS routers with remarkable precision and stealth. Uncovered by researchers at cybersecurity firm GreyNoise, this sophisticated campaign has infected nearly 9,000 routers by exploiting a combination of brute-force tactics, unpatched vulnerabilities, and clever persistence mechanisms.

What’s even more alarming is that this attack doesn’t vanish with a reboot or even a firmware update. The attackers have figured out a way to maintain access indefinitely by injecting their own SSH keys into non-volatile memory, essentially planting a digital backdoor that can’t be easily removed. Discovered in March 2025, this ongoing campaign raises serious concerns for network security worldwide and paints a clear picture of what future botnet threats might look like.

Global ASUS Router Hack: What You Need to Know

In March 2025, cybersecurity researchers at GreyNoise flagged a covert hacking campaign that’s now considered one of the most advanced router-based exploits to date. Detected using their AI-driven tool “Sift,” this operation has compromised nearly 9,000 ASUS routers globally. The attack’s stealth is chilling: only 30 related network requests were spotted over three months, suggesting meticulous planning and evasion strategies.

The attackers deploy a complex four-stage attack method. First, they use brute-force techniques to gain login access, paired with two still-unnamed authentication bypass vulnerabilities. Once in, they exploit CVE-2023-39780, a command injection flaw, to gain deeper system control.

The real ingenuity lies in how they maintain persistence. By enabling SSH access on a custom port (53282) and inserting their own SSH key into the router’s NVRAM, they ensure the backdoor stays open—even after firmware updates or reboots. To cover their tracks, logging functions are also disabled.

ASUS has since released firmware patches addressing CVE-2023-39780 and the authentication bypass issues. However, these updates do not remove previously implanted backdoors. This means that unless an admin manually deletes unauthorized SSH keys and performs a full factory reset, infected routers will remain compromised.

Researchers also traced the attack to four suspicious IP addresses:

101.99.91.151

101.99.94.173

79.141.163.179

111.90.146.237

GreyNoise coordinated with industry and government partners before publicly disclosing the issue, while Sekoia’s independent report later confirmed similar findings under what they call the “ViciousTrap” campaign. The attackers’ advanced knowledge of ASUS hardware suggests a highly resourced threat group, possibly state-sponsored or criminal syndicates aiming to build massive botnet infrastructures.

Network administrators are urged to block the malicious IPs, inspect routers for port 53282 SSH access, and take drastic recovery steps—like full factory resets—to ensure complete remediation.

What Undercode Say:

This ASUS router exploit campaign marks a pivotal moment in how we perceive and prepare for router-based threats. Historically, routers have been overlooked in favor of endpoint and server security, but this incident exposes how overlooked vulnerabilities in consumer and small business networking gear can be silently weaponized on a global scale.

The most critical aspect is persistence through non-volatile memory manipulation. By writing SSH keys to the NVRAM, attackers ensure their foothold is not only secure but practically immune to standard security protocols. This is a sharp deviation from the usual volatile memory exploits, which are cleared upon reboot or patching. This shift indicates a new class of attacks that prioritize long-term access rather than short-term damage.

Another concern is the lack of automatic remediation by ASUS. While patching vulnerabilities is essential, leaving backdoors intact on already-infected devices renders those patches insufficient. It’s like closing the front door after burglars have installed their own back entrance. The onus now lies on system administrators, many of whom may lack the technical skill or awareness to inspect low-level SSH configurations.

GreyNoise’s use of AI-driven detection via “Sift” shows the future of cybersecurity intelligence. Traditional signature-based detection would have missed these attacks due to their minimal footprint. AI can identify anomalies and correlate subtle traffic spikes, offering a more robust defense layer.

On the operational side, the four-stage attack indicates a mature offensive playbook. From brute-force to stealthy persistence, it’s clear these aren’t amateurs. This could be a dry run for a broader campaign, where thousands of routers serve as zombie nodes for DDoS attacks, crypto mining, or even espionage. Given the timing, and the alignment with Sekoia’s ViciousTrap findings, it’s plausible we’re witnessing the build-up of a global botnet infrastructure—something akin to a digital sleeper cell network.

This also raises regulatory and OEM accountability questions. Should companies like ASUS implement automatic forensic scans or post-update SSH audits to ensure infections don’t survive patches? And are ISPs doing enough to monitor and mitigate such threats at the edge?

Ultimately, this campaign is a wake-up call. Routers, often “set and forget” devices, are now frontline battlegrounds in the cyber warfare arena. As attackers grow more silent and strategic, defenders must become more proactive and predictive.

Fact Checker Results:

✔️ Confirmed: CVE-2023-39780 is a real, exploitable vulnerability.

✔️ Verified: Nearly 9,000 ASUS routers were affected, according to Censys.
🚨 Critical: Patching does not remove existing SSH backdoors.

Prediction:

Expect to see more router-focused campaigns leveraging persistence techniques like NVRAM manipulation. If ASUS doesn’t implement automatic post-patch clean-up protocols, compromised devices will remain active assets for future botnet deployments. Security vendors will increasingly rely on AI to detect anomalies in low-noise attacks, while router manufacturers may face mounting pressure to include threat-hunting features in consumer devices by default.

References:

Reported By: cyberpress.org
Extra Source Hub:
https://www.reddit.com/r/AskReddit
Wikipedia
Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 Telegram