Researchers reported multiple campaigns compromising internet-facing edge devices, with ASUS routers and Cisco Small Business/SOHO routers heavily targeted to build stealthy botnets and relay infrastructure. GreyNoise and Censys tracked the AyySSHush campaign abusing legitimate ASUS firmware features, older authentication bypass paths, and CVE-2023-39780 to enable logging functions, add attacker SSH keys, and expose backdoor access on TCP/53282; Censys identified 4,504 likely compromised ASUS devices as of late May, after counts had previously surged above 10,000. Sekoia separately observed a May campaign against ASUS routers using CVE-2021-32030 to enable SSH on the same port, with more than 9,500 potentially affected devices.
At the same time, Sekoia detailed PolarEdge and ViciousTrap, campaigns exploiting CVE-2023-20118 in Cisco routers and extending to devices from QNAP, Synology, and ASUS. PolarEdge used webshells and encrypted TLS backdoors to create an Operational Relay Box network of more than 2,000 devices, while ViciousTrap installed NAT redirection rules to turn compromised systems into a distributed interception layer that forwarded inbound traffic to attacker-controlled servers; Sekoia counted over 5,000 compromised devices across many countries. Investigators also found overlap between the ASUS activity and infrastructure tied to ViciousTrap, suggesting at least some operators are reusing tooling and access across edge-device botnet operations, with residential ISP exposure indicating likely use for proxying, relays, or follow-on cyber activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
On May 30, 2025, Censys published tracking on AyySSHush, detailing its abuse of ASUS firmware features, use of CVE-2023-39780, and overlap with infrastructure previously linked by Sekoia to ViciousTrap.
GreyNoise published research on May 28, 2025 covering the tradecraft of the emergent AyySSHush ASUS botnet campaign.
As of May 28, 2025, Censys identified 4,504 ASUS routers exposing SSH on TCP port 53282, a key indicator of likely AyySSHush compromise.
On May 22, 2025, Sekoia published its investigation into ViciousTrap, describing a honeypot-like interception network built from more than 5,500 compromised edge devices.
On May 12, 2025, Sekoia honeypots detected a new exploit server at 101.99.91.239 targeting ASUS routers and attempting to enable SSH on port 53282 via CVE-2021-32030.
Censys observed a peak of 10,454 exposed ASUS devices with likely AyySSHush indicators on May 7, 2025.
Censys historical data showed the AyySSHush botnet grew to more than 10,000 exposed potentially compromised ASUS routers by May 2025.
In April 2025, Sekoia observed ViciousTrap attempting to reuse a previously documented PolarEdge-related webshell against a Cisco RV042 honeypot.
GreyNoise uncovered the AyySSHush ASUS-router botnet campaign on March 18, 2025, identifying a stealthy compromise chain that installs persistent SSH backdoors.
Sekoia reported the first exploitation attempt attributed to ViciousTrap was observed in March 2025, centered on compromising internet-facing edge devices via CVE-2023-20118.
On February 25, 2025, Sekoia published research describing the PolarEdge botnet's exploitation of CVE-2023-20118, its TLS backdoors, and a global victim set exceeding 2,000 devices.
Censys historical data showed 6,622 potentially compromised ASUS routers in early January 2025, indicating substantial AyySSHush activity at the start of the year.
Sekoia said PolarEdge-related payload submissions dated back to February 2024, providing an early public artifact trail for the botnet's malware.
Sekoia reported the PolarEdge botnet had been active since at least late 2023, targeting edge devices including Cisco, Asus, QNAP, and Synology systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
censys.com
Open sourcelabs.greynoise.io
Open sourceblog.sekoia.io
Open sourceblog.sekoia.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.