Operation WrtHug is a large-scale router hijacking campaign focused on compromising end-of-life and outdated ASUS routers and repurposing them as covert relay infrastructure for espionage-related operations. The activity has been described as China-linked, although public attribution remains unconfirmed. Its operational profile resembles China-associated Operational Relay Box ecosystems that use compromised edge devices to conceal downstream intrusion activity and provide resilient proxy infrastructure. The campaign has affected roughly tens of thousands of routers globally, with especially heavy concentration in Taiwan and additional victim presence in the United States, Russia, Southeast Asia, and Europe. The operation appears to abuse ASUS AiCloud functionality and multiple known vulnerabilities to obtain elevated privileges on vulnerable devices. Operators have chained authentication bypass and command injection techniques to implant persistent SSH backdoors and maintain access across reboots and, in some cases, firmware updates by leveraging legitimate router features. Operation WrtHug demonstrates capabilities consistent with initial access, persistence, privilege escalation, defense evasion, and post-exploitation on network edge devices. The compromised routers function as an Operational Relay Box-style botnet or proxy layer rather than a conventional disruptive botnet, supporting covert traffic routing and infrastructure masking. Reporting has noted limited overlap in exploited-device space with the China-origin AyySSHush, also known as ViciousTrap, but no confirmed operational relationship. Other comparable router-focused ORB ecosystems referenced alongside this activity include LapDogs and PolarEdge. The dominant assessed motivation is espionage, based on the use of globally distributed compromised routers as stealth infrastructure to hide follow-on operations rather than for monetization, ransomware, or destructive effects.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operation WrtHug is a botnet of 50,000+ hacked ASUS routers used to relay and hide espionage operations.
Hijacks ASUS home routers globally for espionage, primarily targeting End-of-Life devices and exploiting known vulnerabilities, with a focus on the AiCloud service.
Mass compromise of end-of-life ASUS WRT routers via ASUS AiCloud using multiple n-day vulnerabilities, deploying persistent SSH backdoors and forming a large network with ORB-like characteristics.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.