A newly discovered campaign has compromised tens of thousands of outdated or end-of-life (EoL) ASUS routers worldwide, primarily in Taiwan, the U.S., and Russia. The compromised devices are part of a massive network. The router compromise activity is being tracked as Operation WrtHug by SecurityScorecard. Southeast Asia and European countries are among the other regions where infections have been recorded.

The attacks likely involve exploiting six known vulnerabilities in ASUS WRT routers that have reached end-of-life (end-of-support) to gain control of the vulnerable devices. All infected routers were found to share a unique self-signed TLS certificate with an expiration date set for 100 years starting in April 2022.
See also: New .NET malware hides Lokibot inside PNG/BMP files
SecurityScorecard reported that 99% of the services presenting the certificate are ASUS AiCloud, a proprietary service designed to allow access to local storage over the internet.
“The WrtHug operation exploits the proprietary AiCloud service with n-day vulnerabilities to gain elevated privileges on ASUS WRT routers that have reached end-of-life,” the company said, adding that the campaign, while not exactly an Operational Relay Box (ORB), bears similarities to other ORBs and botnets linked to China.

Operation WrtHug: Exploiting vulnerabilities in ASUS WRT routers
The attacks likely exploit vulnerabilities tracked as CVE-2023-41345, CVE-2023-41346, CVE-2023-41347, CVE-2023-41348, CVE-2024-12912, and CVE-2025-2492 to spread. Interestingly, the CVE-2023-39780 exploit has also been linked to another Chinese-originated botnet, known as AyySSHush (or ViciousTrap). Two other ORBs that have targeted routers in recent months are LapDogs and PolarEdge.
See also: ServiceNow AI Agents: Abuse of default settings for prompt injection
Of all infected devices, seven IP addresses have been identified as showing signs of compromise related to both WrtHug and AyySSHush (raising the possibility of a correlation between the two attacks/groups). However, there is no evidence to support this hypothesis beyond the shared vulnerability.
The list of router models targeted in the attacks includes:
- ASUS Wireless Router 4G-AC55U
- ASUS Wireless Router 4G-AC860U
- ASUS Wireless Router DSL-AC68U
- ASUS Wireless Router GT-AC5300
- ASUS Wireless Router GT-AX11000
- ASUS Wireless Router RT-AC1200HP
- ASUS Wireless Router RT-AC1300GPLUS
- ASUS Wireless Router RT-AC1300UHP
At present, it is unclear who is behind the operation, but the extensive targeting of Taiwan and overlaps with previous tactics seen in ORB campaigns by Chinese hacking groupssuggest that it may be the work of an unknown group linked to China.
See also: PlushDaemon hackers compromise software updates for cyber espionage

“This research highlights the growing trend of malicious threat actors targeting routers and other network devices in large enterprises,” SecurityScorecard said. “These are typically (but not exclusively) associated with China Nexus hackers, who execute their campaigns in a careful and calculated manner to expand and deepen their global reach.”
“Through a combination of command injections and authentication bypasses, threat actors have managed to deploy persistent backdoors via SSH, often exploiting legitimate router features to ensure their presence survives reboots or firmware updates.“.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
