Asus Router Hack: Thousands Infected with Backdoor
- A new campaign dubbed ViciousTrap is targeting Asus routers, using known vulnerabilities to install backdoors, according to GreyNoise.
- The activity is part of a larger campaign first reported by Sekoia, another security firm.
- The attackers are exploiting vulnerabilities, including CVE-2023-39780, a command injection flaw patched by Asus in a recent firmware update.
Asus routers are under attack! Thousands of devices are being infected with backdoors by the ViciousTrap campaign, exploiting vulnerabilities like CVE-2023-39780. This poses a serious security risk. GreyNoise and Sekoia have detected widespread compromise, urging users to act now. Check your SSH settings for unauthorized access via port 53282 and specific digital certificate keys. News Directory 3 understands this is critical and provides detailed steps to identify and remove the backdoor. Ensure your router firmware is up-to-date and monitor system logs for suspicious activity. Discover what’s next to stay ahead of this evolving threat.
asus Routers Face ViciousTrap Backdoor Campaign
A new campaign dubbed ViciousTrap is targeting Asus routers, using known vulnerabilities to install backdoors, according to GreyNoise. The company detected the malicious activity in mid-March but waited to report it until after notifying government agencies.
The activity is part of a larger campaign first reported by Sekoia, another security firm. Sekoia’s research, using data from censys, suggests that nearly 9,500 Asus routers might potentially be compromised.
The attackers are exploiting vulnerabilities, including CVE-2023-39780, a command injection flaw patched by Asus in a recent firmware update. Other patched vulnerabilities are also being exploited.
Users can check for infection by examining SSH settings in the router’s configuration panel. Compromised routers will show that SSH login is enabled over port 53282 using a specific digital certificate key:
ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAo41nBoVFfj4HlVMGV+YPsxMDrMlbdDZ...
To remove the backdoor, users should delete the identified key and disable the port setting.
System logs showing access from IP addresses 101.99.91[.]151, 101.99.94[.]173, 79.141.163[.]179, or 111.90.146[.]237 may also indicate a compromise. All router users should ensure their devices receive timely security updates to prevent such attacks.
What’s next
Users should immediately check their Asus router settings and update firmware to mitigate the ViciousTrap backdoor campaign. Monitor system logs for suspicious activity and ensure all devices receive regular security updates.
