Get all your news in one place.
100's of premium titles.
One app.
Start reading
Tom’s Hardware
Tom’s Hardware
Technology
Kunal Khullar

RARE PHOTOS: 9 000 asus routers compromised by botnet attack and persistent ssh backdoor that even firmware updates can t fix | Vintage Vibes

Asus RT-BE86U.

Thousands of Asus routers have been compromised due to a newly discovered botnet called ‘AyySSHush.’ The stealth attack was detected in March 2025 by cybersecurity firm GreyNoise, which reportedly exploits authentication and makes use of the router features to maintain long-term access. Notably, the backdoor does not make use of any malware, and the unauthorized access cannot be removed using firmware updates.

The attack begins with threat actors targeting the routers through brute-force login attempts and exploiting authentication bypass techniques, some of which remain undocumented without assigned CVEs. Once inside, they target and exploit CVE-2023-39780, a known command injection vulnerability, to execute arbitrary system-level commands. This technique allows the attackers to manipulate the router’s configuration using legitimate functions within the firmware.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.