Typhoons — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
November 19, 2025
Last Seen
November 19, 2025

Typhoons is a Beijing-linked APT group implicated in a large-scale operation targeting consumer networking devices.

Overview

Typhoons is a Beijing-linked APT group implicated in a large-scale operation targeting consumer networking devices. Recent reporting portrays the group’s campaign as ongoing and evolving, with tens of thousands of ASUS routers compromised, highlighting a focus on IoT device exploitation to establish persistent footholds and potential control over victim networks.

Related Threat Clusters

  • Critical Auth Bypass Vulnerability in Asus DSL Routers

    Asus has identified a critical authentication bypass vulnerability (CVE-2025-59367) affecting its DSL-AC51, DSL-AC750, and DSL-N16 router models. This flaw allows remote, unauthenticated attackers to gain full control…

    14 articles · Updated November 16, 2025
  • Operation WrtHug Compromises Thousands of ASUS Routers Worldwide

    Operation WrtHug has hijacked approximately 50,000 ASUS routers globally, primarily targeting end-of-life models. The campaign is believed to be linked to Chinese threat actors and exploits multiple vulnerabilities,…

    9 articles · Updated November 21, 2025

Recent Intelligence Reports

  • 50k more ASUS routers pwned by evolving Beijing-linked op — Theregister · November 19, 2025
  • Tens of thousands more ASUS routers pwned by suspected, evolving China operation — Theregister · November 19, 2025

CVSS v3.1 Breakdown