ASUS Routers Hacked in Large-Scale Cyber Attack

Paige Henley
Paige Henley Former Editor
Published on: June 4, 2025
Paige Henley Paige Henley Former Editor
Published on: June 4, 2025

More than 9,000 ASUS routers have been hacked in a months-long cyber campaign that may be part of a plan to build a botnet, researchers say.

Hackers gained access by using a known flaw, tracked as CVE-2023-39780, along with brute-force login attempts. Once inside, they could run system commands and stay in control, even after reboots or firmware updates.

ASUS has released a fix, but any routers that were infected before the update may still have backdoors unless certain settings, like SSH access, are turned off.

Cybersecurity firm GreyNoise first spotted the activity in March. It delayed going public while working with government officials and partners to address the issue.

Another report links the attack to a group called ViciousTrap, which has targeted thousands of devices from other brands, too, including Cisco. Cisco has not issued a fix but has provided instructions to reduce the risk.

Experts warn the goal could be to create a network of hacked devices that attackers can control remotely: “This appears to be part of a stealth operation to assemble a distributed network of backdoor devices — potentially laying the groundwork for a future botnet,” wrote GreyNoise.

About the Author
Paige Henley
Paige Henley
Former Editor
Published on: June 4, 2025

About the Author

Paige Henley was an editor at SafetyDetectives. She has three years of experience writing and editing various cybersecurity articles and blog posts about VPNs, antivirus software, and other data protection tools. As a freelancer, Paige enjoys working in a variety of content niches and is always expanding her knowledge base. Outside of work, she raises orphaned neonatal kittens, works on DIY projects around the house, and enjoys movie marathons on weekends with her husband and three cats.