{"id":1688,"date":"2025-05-29T15:05:00","date_gmt":"2025-05-29T12:05:00","guid":{"rendered":"https:\/\/trustcrypt.com\/thousands-of-asus-routers-compromised-in-covert-backdoor-operation\/"},"modified":"2025-05-29T15:05:00","modified_gmt":"2025-05-29T12:05:00","slug":"thousands-of-asus-routers-compromised-in-covert-backdoor-operation","status":"publish","type":"post","link":"https:\/\/trustcrypt.com\/ar\/thousands-of-asus-routers-compromised-in-covert-backdoor-operation\/","title":{"rendered":"Thousands of ASUS Routers Compromised in Covert Backdoor Operation"},"content":{"rendered":"<p>Hackers have gained unauthorized, persistent access to approximately 9,000 ASUS routers in an ongoing exploitation campaign, as reported by cybersecurity intelligence firm GreyNoise.<\/p>\n<p>Distinct from typical malware-based attacks, the perpetrators maintain long-term access without deploying malware or leaving discernible traces. They exploit the routers&#8217; legitimate functionalities to establish persistent backdoors that endure firmware updates and system reboots.<\/p>\n<p>This operation appears to be a component of a covert initiative to assemble a distributed network of compromised devices, potentially setting the stage for future botnet activity.<\/p>\n<p>The tactics utilized in this campaign are reminiscent of those typically employed by advanced persistent threat (APT) groups, which leverage operational relay box (ORB) networks to support prolonged cyber campaigns.<\/p>\n<p>While GreyNoise has refrained from directly attributing the attack to a specific group, the sophistication and operational capability demonstrated suggest that the threat actors are likely both highly skilled and well-resourced.<\/p>\n<p>Targeting ORB devices has been recognized as a prevalent cyber-espionage strategy employed by state-sponsored hackers in recent times.<\/p>\n<p>GreyNoise detailed its findings in a report released on May 28, along with a complementary technical analysis prepared by GreyNoise Labs.<\/p>\n<h3>Intrusion Chain of the ASUS Router Exploitation Campaign<\/h3>\n<p>The malicious campaign was uncovered by GreyNoise researchers on March 18, utilizing an AI-driven network traffic analysis tool called SIFT, coupled with emulated ASUS router profiles within the GreyNoise Global Observation Grid.<\/p>\n<p>SIFT detected unusual network payloads attempting to disable security features from TrendMicro on ASUS routers and exploit existing vulnerabilities. Researchers also noted novel tactics related to ASUS AiProtection features.<\/p>\n<p>Upon tracing the anomalous traffic identified by SIFT, GreyNoise researchers found thousands of compromised routers.<\/p>\n<p>As of May 27, roughly 9,000 routers have been identified as affected, with this number likely to rise.<\/p>\n<p>The analyzed infection chain unfolds as follows:<\/p>\n<p>1. Attackers gain access through brute-force login attempts and exploit two authentication bypass vulnerabilities for which no Common Vulnerabilities and Exposures (CVE) identifiers have yet been assigned.<br \/>\n2. Attackers leverage CVE-2023-39780, a critical command injection vulnerability affecting ASUS RT-AX55, to execute system commands. This vulnerability was subsequently patched in a recent firmware update by ASUS.<br \/>\n3. Attackers exploit legitimate ASUS features to enable SSH access on a custom port (TCP\/53282) and insert an attacker-controlled public key for remote access. The backdoor is stored in non-volatile memory (NVRAM), thus persisting through firmware upgrades and reboots.<br \/>\n4. Attackers disable logging on the routers to evade detection.<\/p>\n<p>Despite the patching of CVE-2023-39780 in a subsequent firmware update, GreyNoise notes that the attacker&#8217;s SSH configuration changes remain intact and can evade removal through regular updates. Initial access methods are patched but also lack assigned CVE identifiers.<\/p>\n<p>GreyNoise initially held off on disclosure of this investigation to inform governmental and industry partners prior to public release. On May 22, cybersecurity firm Sekoia announced the compromise of ASUS routers as part of what it termed the \u201cViciousTrap\u201d campaign.<\/p>\n<h3>Recommendations for Mitigating ASUS Router Vulnerabilities<\/h3>\n<p>In response to the malicious exploitation campaign, GreyNoise has offered several recommendations to mitigate associated threats:<\/p>\n<p>&#8211; Inspect ASUS routers for SSH access on TCP\/53282.<br \/>\n&#8211; Review the <code>authorized_keys<\/code> file for any unauthorized entries.<br \/>\n&#8211; Block the following IP addresses: 101.99.91.151; 101.99.94.173; 79.141.163.179; 111.90.146.237.<br \/>\n&#8211; If compromise is suspected, conduct a full factory reset and manually reconfigure the ASUS router.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers have gained unauthorized, persistent access to approximately 9,000 ASUS routers in an ongoing exploitation campaign, as reported by cybersecurity&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"Default","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[],"tags":[],"class_list":["post-1688","post","type-post","status-publish","format-standard","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Thousands of ASUS Routers Compromised in Covert Backdoor Operation - Trustcrypt<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustcrypt.com\/ar\/thousands-of-asus-routers-compromised-in-covert-backdoor-operation\/\" \/>\n<meta property=\"og:locale\" content=\"ar_AR\" \/>\n<meta property=\"og:locale:alternate\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Thousands of ASUS Routers Compromised in Covert Backdoor Operation\" \/>\n<meta property=\"og:description\" content=\"Hackers have gained unauthorized, persistent access to approximately 9,000 ASUS routers in an ongoing exploitation campaign, as reported by cybersecurity...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/trustcrypt.com\/ar\/thousands-of-asus-routers-compromised-in-covert-backdoor-operation\/\" \/>\n<meta property=\"og:site_name\" content=\"Trustcrypt\" \/>\n<meta property=\"article:published_time\" content=\"2025-05-29T12:05:00+00:00\" \/>\n<meta name=\"author\" content=\"Trustscrypt\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u0643\u064f\u062a\u0628 \u0628\u0648\u0627\u0633\u0637\u0629\" \/>\n\t<meta name=\"twitter:data1\" content=\"Trustscrypt\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 \u062f\u0642\u0627\u0626\u0642\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/trustcrypt.com\/thousands-of-asus-routers-compromised-in-covert-backdoor-operation\/\",\"url\":\"https:\/\/trustcrypt.com\/thousands-of-asus-routers-compromised-in-covert-backdoor-operation\/\",\"name\":\"Thousands of ASUS Routers Compromised in Covert Backdoor Operation\",\"isPartOf\":{\"@id\":\"https:\/\/trustcrypt.com\/#website\"},\"datePublished\":\"2025-05-29T12:05:00+00:00\",\"author\":{\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f\"},\"inLanguage\":\"ar\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/trustcrypt.com\/thousands-of-asus-routers-compromised-in-covert-backdoor-operation\/\"]}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/trustcrypt.com\/#website\",\"url\":\"https:\/\/trustcrypt.com\/\",\"name\":\"Trustcrypt\",\"description\":\"\u0627\u0644\u0623\u0645\u0646 \u0647\u0648 \u0627\u0633\u0645\u0646\u0627 \u0627\u0644\u062b\u0627\u0646\u064a\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/trustcrypt.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"ar\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f\",\"name\":\"Trustscrypt\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g\",\"caption\":\"Trustscrypt\"},\"sameAs\":[\"http:\/\/trustcrypt.com\"],\"url\":\"https:\/\/trustcrypt.com\/ar\/author\/trustscrypt\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Thousands of ASUS Routers Compromised in Covert Backdoor Operation - Trustcrypt","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustcrypt.com\/ar\/thousands-of-asus-routers-compromised-in-covert-backdoor-operation\/","og_locale":"ar_AR","og_type":"article","og_title":"[:en]Thousands of ASUS Routers Compromised in Covert Backdoor Operation[:] - Trustcrypt","og_description":"Hackers have gained unauthorized, persistent access to approximately 9,000 ASUS routers in an ongoing exploitation campaign, as reported by cybersecurity...","og_url":"https:\/\/trustcrypt.com\/ar\/thousands-of-asus-routers-compromised-in-covert-backdoor-operation\/","og_site_name":"Trustcrypt","article_published_time":"2025-05-29T12:05:00+00:00","author":"Trustscrypt","twitter_card":"summary_large_image","twitter_misc":{"\u0643\u064f\u062a\u0628 \u0628\u0648\u0627\u0633\u0637\u0629":"Trustscrypt","\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631":"3 \u062f\u0642\u0627\u0626\u0642"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustcrypt.com\/thousands-of-asus-routers-compromised-in-covert-backdoor-operation\/","url":"https:\/\/trustcrypt.com\/thousands-of-asus-routers-compromised-in-covert-backdoor-operation\/","name":"Thousands of ASUS Routers Compromised in Covert Backdoor Operation","isPartOf":{"@id":"https:\/\/trustcrypt.com\/#website"},"datePublished":"2025-05-29T12:05:00+00:00","author":{"@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f"},"inLanguage":"ar","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustcrypt.com\/thousands-of-asus-routers-compromised-in-covert-backdoor-operation\/"]}]},{"@type":"WebSite","@id":"https:\/\/trustcrypt.com\/#website","url":"https:\/\/trustcrypt.com\/","name":"Trustcrypt","description":"\u0627\u0644\u0623\u0645\u0646 \u0647\u0648 \u0627\u0633\u0645\u0646\u0627 \u0627\u0644\u062b\u0627\u0646\u064a","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustcrypt.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ar"},{"@type":"Person","@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f","name":"Trustscrypt","image":{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g","caption":"Trustscrypt"},"sameAs":["http:\/\/trustcrypt.com"],"url":"https:\/\/trustcrypt.com\/ar\/author\/trustscrypt\/"}]}},"_links":{"self":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts\/1688","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/comments?post=1688"}],"version-history":[{"count":0,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts\/1688\/revisions"}],"wp:attachment":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/media?parent=1688"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/categories?post=1688"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/tags?post=1688"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}