Over 9,000 Asus Routers Breached by Botnet and Persistent SSH Backdoor Resilient to Firmware Updates

Major Security Breach: Over 9,000 ASUS Routers Affected by Botnet Attack

In a troubling development for home and business network security, a sophisticated botnet attack has compromised more than 9,000 ASUS routers. Identified by cybersecurity experts at GreyNoise in March 2025, this incident highlights the alarming exploit known as “AyySSHush.”

At the heart of this attack is a leveraging of vulnerabilities in router authentication processes, combined with the misuse of legitimate router functionalities. These elements have enabled the attackers to create a persistent SSH backdoor within the routers’ non-volatile memory (NVRAM). This unique placement means that the malicious backdoor remains intact regardless of firmware updates or system reboots, making it exceedingly difficult for users to remove.

As the trend of IoT devices grows, so does the potential for such security vulnerabilities. It is essential for users to remain vigilant, regularly update their router settings, and monitor incident reports from reliable cybersecurity sources. This incident serves as a critical reminder of the need for robust security practices in maintaining home and office network safety.

Share this content:

Leave a Reply

Your email address will not be published. Required fields are marked *