AyySSHush is a botnet and operational relay box (ORB)-style campaign targeting internet-exposed ASUS routers to establish durable backdoor access. It has also been linked to the actor tracked as ViciousTrap, and AyySSHush is commonly treated as an alias or closely related designation for that activity. The operation has been associated with Chinese-origin infrastructure or tradecraft, although direct state attribution is not established. The campaign compromises vulnerable or weakly protected edge devices, particularly ASUS routers, through brute-force access attempts against administrative interfaces and exploitation of authentication bypass and command injection vulnerabilities, including CVE-2023-39780. After access is obtained, the operators abuse router functionality to execute commands, weaken or evade built-in protections such as AiProtection, and enable persistent SSH backdoors. Persistence is achieved by modifying settings stored in non-volatile memory, allowing access to survive reboots and even firmware updates. Reporting also links the broader ViciousTrap activity to compromises of edge devices from Linksys, D-Link, QNAP, and Araknis Networks, indicating a wider focus on network appliances suitable for relay infrastructure. The botnet has infected thousands of devices and appears intended to build a large, resilient ORB network for follow-on operations. The observed tradecraft emphasizes initial access, privilege abuse on embedded devices, defense evasion, and long-term persistence rather than overt disruption or ransomware. Known associated naming includes AyySSHush and ViciousTrap.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese-origin botnet activity associated (in this reporting) with exploitation of CVE-2023-39780; possible but unproven overlap with Operation WrtHug based on shared indicators and router targeting patterns.
Botnet campaign backdooring thousands of ASUS routers, persisting through reboots and firmware updates, and likely contributing infected devices to a larger ORB network.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.