Executive Summary
In late 2025, tens of thousands of end-of-life ASUS routers worldwide were hijacked in a large-scale operation dubbed "WrtHug." The attackers exploited six unpatched vulnerabilities in outdated ASUS WRT firmware, targeting devices primarily in Taiwan, the U.S., and Russia, among others. After gaining unauthorized access, WrtHug actors enrolled these routers into a global botnet, leveraging them for coordinated command-and-control traffic and potentially for further attacks. The campaign highlighted the sustained risk posed by unsupported network equipment in both consumer and business environments.
This incident underscores an ongoing surge in attacks targeting aging and end-of-life IoT devices, as cybercriminals capitalize on lapses in patching and lifecycle management. Organizations globally are under renewed pressure to inventory, segment, and securely retire vulnerable network infrastructure as such botnet tactics intensify.
Why This Matters Now
Botnet operations leveraging obsolete infrastructure are surging, posing a major threat to both consumer privacy and enterprise network security. Operation WrtHug demonstrates how unpatched, end-of-life routers can be weaponized at scale, making urgent the need for organizations to assess, segment, and replace outdated network devices to mitigate evolving risk.
Attack Path Analysis
Attackers initiated Operation WrtHug by exploiting multiple unpatched vulnerabilities on end-of-life ASUS routers exposed to the internet. After initial access, they likely elevated privileges to gain persistent control over device functions and execution contexts. Compromised routers were then used as lateral launch points to extend botnet membership and spread malicious payloads within local and remote networks. Command and control channels were established, enabling distributed management of infected devices across global infrastructure via encrypted or covert channels. Exfiltration methods may have been used to siphon data or configuration details from the routers, while the overall impact resulted in the formation of a large-scale botnet capable of further attacks, disruptions, or malicious monetization.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited six known vulnerabilities in unpatched, internet-facing ASUS routers to gain unauthenticated remote access.
Related CVEs
CVE-2023-41345
CVSS 8.8An OS command injection vulnerability in ASUS WRT routers allows authenticated remote attackers to execute arbitrary commands via the token module.
Affected Products:
ASUS WRT Routers – Multiple versions
Exploit Status:
exploited in the wildCVE-2023-41346
CVSS 8.8An OS command injection vulnerability in ASUS WRT routers allows authenticated remote attackers to execute arbitrary commands via the token module.
Affected Products:
ASUS WRT Routers – Multiple versions
Exploit Status:
exploited in the wildCVE-2023-41347
CVSS 8.8An OS command injection vulnerability in ASUS WRT routers allows authenticated remote attackers to execute arbitrary commands via the token module.
Affected Products:
ASUS WRT Routers – Multiple versions
Exploit Status:
exploited in the wildCVE-2023-41348
CVSS 8.8An OS command injection vulnerability in ASUS WRT routers allows authenticated remote attackers to execute arbitrary commands via the token module.
Affected Products:
ASUS WRT Routers – Multiple versions
Exploit Status:
exploited in the wildCVE-2023-39780
CVSS 8.8A command injection vulnerability in ASUS WRT routers allows authenticated remote attackers to execute arbitrary commands.
Affected Products:
ASUS WRT Routers – Multiple versions
Exploit Status:
exploited in the wildCVE-2024-12912
CVSS 7.2An arbitrary command execution vulnerability in ASUS WRT routers allows remote attackers to execute arbitrary commands via the AiCloud service.
Affected Products:
ASUS WRT Routers – Multiple versions
Exploit Status:
exploited in the wildCVE-2025-2492
CVSS 9.2An improper authentication control vulnerability in ASUS WRT routers with AiCloud enabled allows remote attackers to bypass authentication and execute arbitrary functions.
Affected Products:
ASUS WRT Routers – Multiple versions
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Modify Authentication Process
Hijack Execution Flow
Valid Accounts
Network Service Discovery
Network Share Discovery
Non-Application Layer Protocol
Phishing
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security of System Components Not Supported by Vendor
Control ID: 6.4.2
NYDFS 23 NYCRR 500 – Application Security
Control ID: 500.08
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Art. 9
CISA ZTMM 2.0 – Asset Discovery and Classification
Control ID: Asset Management – 2.1
NIS2 Directive – Incident Prevention and Risk Management
Control ID: Art. 21(2)(b)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Critical network infrastructure vulnerability through compromised ASUS routers enables botnet recruitment, lateral movement, and encrypted traffic interception across telecommunications backbone systems.
Financial Services
End-of-life router exploitation creates massive compliance violations for PCI and banking regulations while enabling data exfiltration and east-west traffic compromise in financial networks.
Health Care / Life Sciences
WrtHug botnet compromises medical network segmentation and HIPAA compliance through router hijacking, exposing patient data transmission and enabling healthcare system lateral movement attacks.
Government Administration
Tens of thousands of compromised routers create national security risks through government network infiltration, enabling threat detection evasion and potential state-sponsored surveillance operations.
Sources
- WrtHug Exploits Six ASUS WRT Flaws to Hijack Tens of Thousands of EoL Routers Worldwidehttps://thehackernews.com/2025/11/wrthug-exploits-six-asus-wrt-flaws-to.htmlVerified
- Operation WrtHug Targets Over 50,000 ASUS Routers to Build a Global Botnethttps://www.thaicert.or.th/en/2025/11/21/operation-wrthug-targets-over-50000-asus-routers-to-build-a-global-botnet/Verified
- ASUS Router Flaw Linked to China’s Operation WrtHug Espionage Campaignhttps://botcrawl.com/asus-router-flaw-linked-to-wrthug-espionage-campaign/Verified
- 50,000 ASUS routers hacked in the WrtHug campaignhttps://hackmag.com/news/wrthugVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, east-west and egress policy enforcement, and continuous threat detection would have significantly limited the attacker's ability to exploit exposed assets, move laterally, establish C2, and leverage compromised routers for botnet growth. CNSF controls enforcing workload isolation and outbound filtering are critical to breaking this attack chain.
Control: Cloud Firewall (ACF)
Mitigation: Blocked initial exploit attempts at the network perimeter.
Control: Threat Detection & Anomaly Response
Mitigation: Detected abnormal privilege elevation and alerted security teams.
Control: Zero Trust Segmentation
Mitigation: Prevented unauthorized east-west traversal between network segments.
Control: Egress Security & Policy Enforcement
Mitigation: Blocked or detected C2 communication attempts to external destinations.
Control: Inline IPS (Suricata)
Mitigation: Detected and alerted on suspicious outbound data transfers.
Accelerated identification and remediation of compromised assets.
Impact at a Glance
Affected Business Functions
- Network Infrastructure
- Remote Access Services
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive network configurations and user data due to unauthorized access and control of compromised routers.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce perimeter controls with robust cloud-native firewalls to block known exploits against exposed services.
- • Implement identity-based Zero Trust segmentation to restrict lateral movement among workloads and network segments.
- • Deploy continuous threat detection and anomaly response for privileged operations on all infrastructure endpoints.
- • Apply strict egress filtering and DNS/FQDN-based outbound controls to prevent C2 and exfiltration attempts.
- • Maintain centralized network and security visibility to rapidly identify, contain, and remediate compromised assets in multicloud and hybrid environments.



