Over 9,000 ASUS routers have been compromised by a new botnet dubbed “AyySSHush,” which has also been observed targeting home office (SOHO) routers from Cisco, D-Link , and Linksys.
See also: PumaBot botnet forces SSH credentials to compromise devices

This malicious campaign was detected by security researchers at GreyNoise in mid-March 2025. According to their report, it bears characteristics typically associated with state-owned threat actors, although no official claim of responsibility has been made.
The threat monitoring firm says the attacks combine techniques such as brute-force attacks on login credentials, bypassing authentication mechanisms, and exploiting older vulnerabilities to compromise ASUS routers, including the RT-AC3100, RT-AC3200 , and RT-AX55. Specifically, the attackers exploit an old command injection vulnerability, CVE-2023-39780, to add their own SSH public key and enable the SSH daemon to listen on the non-standard TCP port 53282.These modifications allow attackers to maintain backdoor access to the device, even after reboots or firmware.
The attack is particularly discreet, as it does not involve the use of malware, while the attackers disable both logging and Trend Micro 's AiProtection feature in order to avoid detection.
For example, GreyNoise says it has recorded just 30 malicious requests related to this AyySSHush Botnet campaign over the past three months, despite 9,000 ASUS routers being infected. However, only three of these requests were enough to trigger GreyNoise’s AI analysis tool, which flagged them for further human investigation.
See also: DanaBot Botnet operation disrupted, 16 suspects found
The campaign in question appears to be related to the activity being monitored by Sekoia, dubbed “Vicious Trap,” which was uncovered last week. The French cybersecurity firm reported that cybercriminals are exploiting the CVE-2021-32030 to compromise ASUS routers.

In the campaign observed by Sekoia, attackers are reportedly targeting SOHO routers, SSL VPNs, video recorders (DVRs), and BMC controllers from D-Link, Linksys, QNAP , and Araknis Networks.
The exact operational goal of the AyySSHush botnet remains unclear, as there is no evidence of distributed denial of service (DDoS) attacks or the devices being used as proxies to funnel malicious traffic through ASUS routers.
However, in the router breaches recorded by Sekoia, a malicious script was observed to be downloaded and executed, which redirects network traffic from the compromised system to third-party devices controlled by the attacker.
For now, it appears that the campaign is silently building a network of routers with installed backdoors, paving the way for the creation of a future botnet.
See also: New XorDDoS malware allows creation of DDoS botnets
The creation of a “silent” botnet, as appears to be the case here, can be the first stage for future large-scale coordinated attacks, such as massive DDoS, attacks on cloud infrastructure, or even targeted espionage. The fact that no immediate malicious use of the infrastructure is observed is often indicative of a strategic approach by more sophisticated and possibly state-backed actors.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
