Threat Intelligence, Network Security, IoT

China-linked hackers hijack thousands of ASUS routers

WirelessRouter2

Security Brief Asia reports that a widespread cyberespionage campaign, dubbed "Operation WrtHug," has compromised thousands of ASUS routers globally, with SecurityScorecard's STRIKE team attributing the activity to a China-linked threat actor.

The campaign has disproportionately targeted users in Taiwan, which accounts for nearly half of all infected devices, while notably avoiding mainland China. The operation exploits end-of-life ASUS router models that no longer receive security updates, leveraging known vulnerabilities in proprietary applications like AiCloud.

A key technical indicator of compromise is the presence of a unique, self-signed TLS certificate with an unusually long 100-year expiration date installed on the hijacked devices. Gilad F. Maizles, a SecurityScorecard researcher, described the operation as a "case study in how nation-state actors are embedding themselves in consumer infrastructure to build stealthy, resilient, global espionage networks."

The campaign's focus on consumer and small office/home office devices reflects a strategic shift by state-backed groups to use widely distributed, hard-to-trace infrastructure for relaying traffic and conducting stealthy operations.

An In-Depth Guide to Network Security

Get essential knowledge and practical strategies to fortify your network security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds