Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory

operation_wrthug

Also known asOperation WrtHug

Operation WrtHug is the name given by SecurityScorecard’s STRIKE team to a large-scale router hijacking campaign and ORB-like botnet activity involving approximately 50,000 compromised ASUS routers globally. The activity is described as China-linked, though attribution is not confirmed; SecurityScorecard states the campaign is not exactly an Operational Relay Box (ORB) but bears similarities to China-linked ORBs and botnet-style infrastructure, and the targeting patterns and tactical overlap suggest a possible China-affiliated actor. The campaign has heavily affected outdated and end-of-life ASUS WRT routers, with significant concentrations in Taiwan, the United States, and Russia, and additional infections observed in Southeast Asia and Europe. Reported targeted models include ASUS 4G-AC55U, 4G-AC860U, DSL-AC68U, GT-AC5300, GT-AX11000, RT-AC1200HP, RT-AC1300GPLUS, and RT-AC1300UHP. SecurityScorecard assessed that the operators leveraged ASUS AiCloud and multiple known n-day vulnerabilities to gain high privileges on exposed devices, including likely exploitation of CVE-2023-41345, CVE-2023-41346, CVE-2023-41347, CVE-2023-41348, CVE-2024-12912, and CVE-2025-2492. The operators reportedly chained command injection and authentication bypass techniques to deploy persistent SSH backdoors, often abusing legitimate router features to survive reboots or firmware updates. Infected routers were observed presenting a distinctive self-signed TLS certificate with a 100-year expiration from April 2022; 99% of services presenting that certificate were identified as ASUS AiCloud. The campaign has been characterized as an espionage-enabling global relay network or 'global spy network.' SecurityScorecard noted limited overlap with the Chinese-origin botnet AyySSHush, also known as ViciousTrap, including seven IPs showing signs of compromise associated with both, but stated there is no evidence of a direct relationship beyond shared vulnerability exploitation. Other ORB campaigns referenced for comparison include LapDogs and PolarEdge. Known alias: operation_wrthug.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

5 of 15 tactics7 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
2 techniques
T1078
Valid Accounts
T1190
Exploit Public-Facing Application
TA0002
Execution
1 technique
T1059
Command and Scripting Interpreter
T1059.004
Unix Shell
TA0003
Persistence
1 technique
T1078
Valid Accounts
TA0004
Privilege Escalation
1 technique
T1078
Valid Accounts
TA0005
Stealth
1 technique
T1078
Valid Accounts
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping3

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.