Security researchers at GreyNoise have discovered a sophisticated attack targeting thousands of Asus routers globally. A nation-state or highly-resourced actor exploited unpatched vulnerabilities to install a backdoor, granting persistent administrative access even after reboots and firmware updates. The attackers achieved this by chaining authentication bypasses and abusing legitimate configuration features. Approximately 9,000 infected devices have been identified, with the number continuing to rise. While no malicious activity has yet been observed, the compromised routers likely represent a large-scale botnet in development.
Prepared by Jonathan Pierce and reviewed by editorial team.
Comments