GreyNoise researchers detail a novel botnet infecting 9K+ routers from Asus and others with a persistent SSH backdoor, enabling access after reboots and updates
What You Need To Know Shweta Sharma / CSO : New botnet hijacks AI-powered security tool on Asus routers Bruno Ferreira / HotHardware : ASUS Routers Hit By Stealthy Backdoor Botnet Attack That Evades Firmware Upgrades Jane McCallion / ITPro : Asus routers at risk from backdoor vulnerability Dan Goodin / Ars Technica : Thousands of Asus routers are being hit with stealthy, persistent backdoors Lance Whitney / ZDNET : Your Asus router may be compromised - here's how to tell and what to do Emily Forlini / PCMag : Cybercriminals Hack Asus Routers: Here's How to Check If They Got Into Yours Marcus Mendes / 9to5Mac : In the market for a new router? Here are 13 models to avoid, according to the FBI Jean Leon / Android Headlines : ASUS Router Alert: Thousands Hacked to Form Massive Botnet Aminu Abdullahi / eSecurity Planet : Over 9,000 Routers Hijacked: ASUS Users Caught in Ongoing Cyber Operation Alfonso Maruccia / TechSpot : Thousands of Asus routers compromised by “ViciousTrap” backdoor Hilbert Hagedoorn / Guru3D : ASUS Routers Vulnerable: Hackers Implant Undetectable Backdoors in NVRAM Prajeet Nair / HealthcareInfoSecurity.com : Thousands of ASUS Routers Hit by Persistent Backdoor The GreyNoise Blog : GreyNoise Discovers Stealthy Backdoor Campaign Affecting Thousands of ASUS Routers Bluesky: Catalin Cimpanu / @campuscodi.risky.biz : More than 9,000 ASUS routers have been infected by a new botnet named AyySSSHush. — The botnet's attacks disable a TrendMicro security feature embedded in ASUS routers and then exploits older vulnerabilities. — www.labs.greynoise.io/grimoire/ 202... Forums: r/cybersecurity : Thousands of Asus routers are being hit with stealthy, persistent backdoors r/privacy : Thousands of Asus routers are being hit with stealthy, persistent backdoors | Backdoor giving full administrative control can survive reboots and firmware updates. r/gadgets : Thousands of Asus routers are being hit with stealthy, persistent backdoors | Backdoor giving full administrative control can survive reboots and firmware updates. r/HomeNetworking : Thousands of Asus routers are being hit with stealthy, persistent backdoors | Attacker Dubbed “ViciousTrap” Adds SSH Backdoor r/technews : Thousands of Asus routers are being hit with stealthy, persistent backdoors | Backdoor giving full administrative control can survive reboots and firmware updates. BeauHD / Slashdot : ASUS Router Backdoors Affect 9,000 Devices, Persists After Firmware Updates 3
Context & Ripple Effects
This campaign extends a long-running pattern of router backdoors, from stealthy Cisco compromises across multiple countries to actively exploited backdoors in low-cost consumer networking gear. What distinguishes the reported ASUS-focused operation is persistence through the recovery steps owners commonly rely on: reboots and firmware updates.
ASUS has also faced a separate supply-chain compromise in which its update tooling delivered a backdoor to Windows systems. That history makes the reported disabling of an embedded router security feature especially consequential: the attack is aimed not merely at gaining entry, but at retaining administrative control.
First-order effects
- Affected router owners can remain exposed after a reboot or firmware update because the implanted SSH access is designed to persist; restoring trust may require remediation beyond ordinary patching.
- ASUS must address a campaign affecting thousands of routers and the reported interference with its embedded TrendMicro security feature, while affected networks face continued unauthorized administrative access.
Second-order effects
- Router vendors and managed-network operators will need to treat firmware currency as insufficient evidence of a clean device, increasing the value of configuration review and credential/access verification.
- The campaign reinforces the operational risk of security features embedded in network appliances: if an attacker can disable or bypass them, their presence can create false confidence rather than a reliable containment layer.
Third-order effects
- If persistent router compromises become more common, consumer and small-business networking will shift from patch-centric maintenance toward stronger device-state verification and recovery mechanisms.
- The recurring record of backdoors in consumer routers and this ASUS-focused campaign suggests home-network infrastructure will remain an attractive, durable foothold unless vendors make compromise detection and trustworthy reset paths more robust.
The trend: Persistent compromise of edge devices is pushing router security beyond vulnerability patching toward proving that a device's administrative state is trustworthy.