Thousands of ASUS Routers Compromised by Persistent Backdoor Exploit

Overview

A sophisticated cyberattack has compromised over 9,000 ASUS routers worldwide, establishing persistent backdoors that survive both firmware updates and device reboots. This campaign, uncovered by cybersecurity firm GreyNoise, leverages a combination of known and previously undisclosed vulnerabilities to gain unauthorized access, potentially laying the groundwork for a large-scale botnet.(infosecurity-magazine.com, esecurityplanet.com)

How the Attack Works

The attackers employ a multi-step approach:(runzero.com)

  1. Initial Access: Gained through brute-force login attempts and exploitation of authentication bypass vulnerabilities, including CVE-2023-39780—a command injection flaw. (greynoise.io)
  2. Establishing Persistence: Once access is obtained, the attackers enable SSH on a non-standard port (TCP/53282) and insert their own SSH public keys into the router’s configuration. These changes are stored in non-volatile memory (NVRAM), ensuring persistence even after firmware updates or reboots. (esecurityplanet.com)
  3. Stealth Measures: The attackers disable logging features to avoid detection and do not deploy traditional malware, making the compromise difficult to identify. (greynoise.io)

Scope of the Breach

As of late May 2025, approximately 9,000 ASUS routers have been confirmed compromised, with the number continuing to grow. The affected devices are primarily those exposed directly to the internet, commonly found in home and small office environments. (greynoise.io, esecurityplanet.com)

Potential Threat Actors

While GreyNoise has not attributed the attack to a specific group, the tactics and sophistication suggest involvement by advanced persistent threat (APT) actors. French cybersecurity firm Sekoia has linked the campaign to a group they refer to as “ViciousTrap,” known for targeting various network devices to create a network of compromised systems. (esecurityplanet.com)

Recommended Actions for ASUS Router Owners

If you own an ASUS router, especially models like RT-AC3200, RT-AC3100, or RT-AX55, take the following steps:

  1. Check for Unauthorized SSH Access:
  2. Update Firmware:
    • Ensure your router’s firmware is updated to the latest version, which addresses known vulnerabilities like CVE-2023-39780.(greynoise.io)
  3. Perform a Factory Reset:
    • Conduct a full factory reset to remove any persistent backdoors stored in NVRAM.
    • Manually reconfigure your router settings post-reset.(greynoise.io, thesun.co.uk)
  4. Block Malicious IP Addresses:
    • Add the following IPs to your router’s blocklist:
      • 101.99.91.151
      • 101.99.94.173
      • 79.141.163.179
      • 111.90.146.237
  5. Monitor for Unusual Activity:

Conclusion

This incident underscores the importance of proactive cybersecurity measures, especially for devices exposed to the internet. Regularly updating firmware, monitoring for unauthorized access, and performing factory resets when necessary can help protect against such sophisticated attacks. As cyber threats evolve, staying informed and vigilant is crucial to safeguarding your digital infrastructure.

Sources:

  • GreyNoise. “GreyNoise Discovers Stealthy Backdoor Campaign Affecting Thousands of ASUS Routers.”
  • SC Media. “ASUS router backdoors affect 9K devices, persist after firmware updates.”
  • Cybersecurity Dive. “Thousands of ASUS routers compromised in sophisticated hacking campaign.”
  • eSecurity Planet. “ASUS Users Caught in Ongoing Cyber Operation.”

Leave a Comment