Earlier topic posted in the networking subforum:
https://broadbandbulletin.com/d/3391-thousands-of-asus-routers-are-being-hit-with-stealthy-persistent-backdoors
Anyway…
https://www.greynoise.io/blog/stealthy-backdoor-campaign-affecting-asus-routers
https://www.labs.greynoise.io/grimoire/2025-03-28-ayysshush/
From the arstechnica article:
The attackers are backdooring the devices by exploiting multiple vulnerabilities. One is CVE-2023-39780, a command-injection flaw that allows for the execution of system commands, which Asus patched in a recent firmware update, GreyNoise said. The remaining vulnerabilities have also been patched but, for unknown reasons, have not received CVE tracking designations.
The only way for router users to determine whether their devices are infected is by checking the SSH settings in the configuration panel. Infected routers will show that the device can be logged in to by SSH over port 53282 using a digital certificate with a truncated key of: ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAo41nBoVFfj4HlVMGV+YPsxMDrMlbdDZ…
To remove the backdoor, infected users should remove the key and the port setting.
People can also determine if they’ve been targeted if system logs indicate that they have been accessed through the IP addresses 101.99.91[.]151, 101.99.94[.]173, 79.141.163[.]179, or 111.90.146[.]237. Users of any router brand should always ensure their devices receive security updates in a timely manner.
Or one can update to the latest firmware for their Asus router, then do a hard factory reset on their Asus router followed by a manual configuration. Do not import a saved router.cfg file.