Thousands of ASUS routers worldwide have been compromised in a hijacking campaign thought to be linked to China, according to new findings from the STRIKE threat intelligence team at SecurityScorecard. The incident, named Operation "WrtHug," primarily affects users in Taiwan but has also impacted networks in the United States, Russia, Southeast Asia, and several European countries.
The operation has targeted an array of ASUS router models, including RT-AC1300UHP, GT-AX11000, and DSL-AC68U. SecurityScorecard confirmed that almost half of the compromised routers are in Taiwan. No evidence was found of infected devices in mainland China.
A notable feature across all hijacked routers is a unique, self-signed TLS certificate with a century-long expiration date. SecurityScorecard researchers identified this as an important indicator that the routers have been compromised. This uniform technical approach suggests a well-organised and coordinated campaign.
The targeting of end-of-life (EoL) ASUS routers reflects a broader trend in state-backed cyber espionage. Attackers are exploiting consumer and small office/ office (SOHO) infrastructure to build distributed networks that can relay traffic, support stealth activities, and remain resilient against takedown efforts.
The campaign has focused on routers that are no longer officially supported by ASUS, exploiting outdated proprietary applications such as AiCloud. Many vulnerabilities used in the attack, including CVE-2023-39780, have been known for some time. SecurityScorecard links the exploit to another operation known as "AyySSHush." Seven IP addresses displayed indications of compromise from both campaigns, suggesting potential collaboration or an evolving singular threat group.
The use of a self-signed TLS certificate with an expiry period of 100 years stands out as an unusual technical feature. Analysts recommend that organisations and IT leaders treat such indicators as potential red flags and audit their networks for similar signs of compromise.
The operation's focus on devices that have reached their end of support means they lack security updates or patches, making them vulnerable to exploitation. Remote access applications bundled with these routers, such as AiCloud, appear to have played a role in enabling the intrusions.
The lack of infections in mainland China, despite widespread targeting elsewhere, is being viewed as a data point in support of speculation the campaign's origin. SecurityScorecard researchers observed a strong focus on infrastructure in Taiwan, accounting for between 30 to 50 percent of the overall targeting. Additional clusters appear in major regions globally, potentially as a means to build wider espionage relay capabilities.
Security experts are encouraging organisational leaders to review and update their hardware inventories and to apply additional scrutiny to legacy equipment that may no longer be supported or receive updates.
"The deliberate targeting of End-Of-Life ASUS devices by compromising proprietary applications and services such as AiCloud, reflect growing strategic interest in SOHO devices. This shows us the willingness of threat actors to specialise in targeting them as reliable staging points," said Maizles.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
