Global Botnets Exploit Router Vulnerabilities to Maintain Persistent Backdoors

1 min read
Source: BleepingComputer
Global Botnets Exploit Router Vulnerabilities to Maintain Persistent Backdoors
Photo: BleepingComputer
TL;DR Summary

A new botnet named 'AyySSHush' has compromised over 9,000 ASUS routers by exploiting an old vulnerability to install a persistent SSH backdoor, allowing attackers to maintain access even after reboots or firmware updates. The campaign, possibly linked to a nation-state actor, also targeted other SOHO routers from Cisco, D-Link, and Linksys, and involves stealthy techniques to evade detection. ASUS has released security patches, and users are advised to update firmware, check for suspicious files, and reset their devices if compromised.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

2 min

vs 3 min read

Condensed

83%

48380 words

Want the full story? Read the original article

Read on BleepingComputer