Security Stop-Press: Asus Routers Hit by Stealth Backdoor Attack

June 5, 2025

Security Stop-Press: Asus Routers Hit by Stealth Backdoor Attack

Thousands of Asus routers have been compromised in a silent, persistent attack that gives hackers remote access, even after firmware updates.

Cybersecurity firm GreyNoise uncovered the campaign, which targets internet-facing Asus models like the RT-AC3100 and RT-AX55. Attackers use brute-force logins or old vulnerabilities to gain admin access, then exploit a flaw (CVE-2023-39780) to enable hidden logging features and install a stealthy backdoor.

SSH access is then enabled through official settings, with an attacker-controlled key added. GreyNoise warns this “persists across firmware upgrades” and may be part of a long-term botnet operation, with over 4,800 affected devices already detected.

Businesses using Asus routers should check for SSH on port 53282, inspect authorised\_keys, and block known malicious IPs. If compromise is suspected, only a full factory reset can remove the backdoor.

Security Stop-Press: Blur Your Property on Google Maps for Better Security
July 16, 2025
Blurring your property on Google Maps is a simple, permanent step available to any homeowner or tenant that may help reduce the risk of targeted crime.
Featured Article : AI Agents Failing (40% Cancellations Predicted)
July 16, 2025
New research has found that 70 per cent of AI agents struggle to complete standard office tasks successfully, while Gartner warns that over 40 per cent of current agentic AI projects will be scrapped by the end of 2027.
More Posts