{"id":133823,"date":"2025-11-19T15:58:56","date_gmt":"2025-11-19T15:58:56","guid":{"rendered":"https:\/\/cybersecuritynews.com\/?p=133823"},"modified":"2025-11-19T16:01:25","modified_gmt":"2025-11-19T16:01:25","slug":"wrthug-asus-routers","status":"publish","type":"post","link":"https:\/\/cybersecuritynews.com\/wrthug-asus-routers\/","title":{"rendered":"Massive Hacking Operation WrtHug Compromises Thousands of ASUS Routers Worldwide"},"content":{"rendered":"\n<p>A sophisticated cyber campaign known as Operation WrtHug has hijacked tens of thousands of ASUS WRT routers globally, turning them into potential espionage tools for suspected China-linked hackers.<\/p>\n\n\n\n<p>SecurityScorecard&#8217;s STRIKE team, in collaboration with ASUS, revealed the operation on November 18, 2025, highlighting how attackers exploited outdated firmware to build a stealthy network infrastructure.<\/p>\n\n\n\n<p>This breach underscores the rising threat to end-of-life consumer devices, with infections concentrated in Taiwan and spreading to the U.S., Russia, and Southeast Asia.\u200b<\/p>\n\n\n\n<p>Researchers first detected Operation WrtHug through a suspicious self-signed <a href=\"https:\/\/cybersecuritynews.com\/staying-on-top-of-tls-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">TLS certificate<\/a> shared across compromised devices, featuring an unusually long 100-year expiration date from April 2022.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEif9CKxrXQ2KN4PvIj_SUA5JJAiuE4tvnXbETR6NTGpsjjgTNxVCvghcFGiuO3YArV61QAHyPfRrotL-nmqXiPv2WBcjMVdR6m-p-nOpF-dVl5_Xt3DPF_nYi5zXfIHAdapnv3OEgO6gm7HRDOOxZMh4X_NcfYBY6308MCmoQDXfdQAO9YMQ7zorw_trbt4\/w564-h640\/SSl%20Cerrtificate.webp\" alt=\"WrtHug ASUS Routers\"\/><figcaption class=\"wp-element-caption\">maliciosu SSL Certificate <\/figcaption><\/figure><\/div>\n\n\n<p>This certificate, with SHA1 thumbprint 1894a6800dff523894eba7f31cea8d05d51032b4, appeared on 99% of affected ASUS AiCloud services, a feature meant for remote home network access but now exploited as an entry point.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi1-T2idMkgkIJVt2lySDUh1weh6dQWlgn9WxVQFZE1eBTqTrLlvRCEUBHX2GBE_ydZyOHk5BEG83djuHL3rXrJCNnfii5EvrbSCDxTg7J63cJSwWpyM-Ybl59VsmAVZ9hJHucpVQ3ajamv4-5CIv8NXxnCIHqYJdE4agDWl3QoRnsvg6-6vTztSKL75tts\/w640-h602\/assus.webp\" alt=\"WrtHug ASUS Routers\"\/><figcaption class=\"wp-element-caption\">Router Login<\/figcaption><\/figure><\/div>\n\n\n<p>The campaign targets exclusively ASUS WRT models, many of which are end-of-life and unpatched, allowing attackers to inject commands and gain root privileges without altering the device&#8217;s outward appearance.<\/p>\n\n\n\n<p>The operation&#8217;s scale is alarming, with estimates of 50,000 unique IP addresses involved over the past six months, based on proprietary scans and tools like Driftnet.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEivrOgljKKibavsG22YQp_Im1zxYnszFBurl1_JJNQl_VnFqLFtAhNmN7-9X6ndoj_YKuAs9y09D616c4lj10RvFLUshnWGDdplil-gA9MHrL5pqY7d7CZyPvOcLoj-XR7T58xNSzj7338yB9OB6W70Ytp25yTLkVV6t93WfJgCiWJ7rXRZnHapG5tzPN7e\/s16000\/WrtHug.webp\" alt=\"WrtHug ASUS Routers\"\/><figcaption class=\"wp-element-caption\">Heatmap<\/figcaption><\/figure>\n\n\n\n<p>Unlike random botnets, WrtHug shows a deliberate geographic focus, infecting 30-50% of devices in Taiwan, a pattern that aligns with geopolitical tensions. Smaller clusters hit South Korea, Japan, Hong Kong, central Europe, and the U.S., but mainland China remains largely untouched, aside from Hong Kong.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"exploited-vulnerabilities\"><strong>Exploited Vulnerabilities<\/strong><\/h2>\n\n\n\n<p>Attackers chained six known flaws in ASUS firmware to propagate the malware, focusing on N-day exploits in AiCloud and OS injection vectors, SecurityScorecard <a href=\"https:\/\/securityscorecard.com\/wp-content\/uploads\/2025\/11\/STRIKE_Asus_WrtHug-Report_V6.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">said to<\/a> CybersecurityNews.<\/p>\n\n\n\n<p>These vulnerabilities, all patched by ASUS, primarily affect outdated routers running lighttpd or <a href=\"https:\/\/cybersecuritynews.com\/hackers-attacking-apache-web-servers\/\" target=\"_blank\" rel=\"noreferrer noopener\">Apache web servers<\/a>.<\/p>\n\n\n\n<p>The table below details the key CVEs, their impacts, and prerequisites:\u200b<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>CVE ID<\/th><th>Affected Products<\/th><th>Impact<\/th><th>Exploit Prerequisites<\/th><th>CVSS Score<\/th><\/tr><\/thead><tbody><tr><td>CVE-2023-41345<\/td><td>ASUS WRT routers<\/td><td>OS command injection<\/td><td>Authenticated access, token module flaw<\/td><td>8.8<\/td><\/tr><tr><td>CVE-2023-41346<\/td><td>ASUS WRT routers<\/td><td>OS command injection<\/td><td>Authenticated access, token module flaw<\/td><td>8.8<\/td><\/tr><tr><td>CVE-2023-41347<\/td><td>ASUS WRT routers<\/td><td>OS command injection<\/td><td>Authenticated access, token module flaw<\/td><td>8.8<\/td><\/tr><tr><td>CVE-2023-41348<\/td><td>ASUS WRT routers<\/td><td>OS command injection<\/td><td>Authenticated access, token module flaw<\/td><td>8.8<\/td><\/tr><tr><td>CVE-2024-12912<\/td><td>ASUS WRT routers<\/td><td>Arbitrary command execution<\/td><td>Remote access via AiCloud<\/td><td>7.2<\/td><\/tr><tr><td>CVE-2025-2492<\/td><td>ASUS WRT routers<\/td><td>Unauthorized function execution<\/td><td>Improper authentication control<\/td><td>9.2<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>These flaws link to CVE-2023-39780, a <a href=\"https:\/\/cybersecuritynews.com\/tag\/command-injection\/\" target=\"_blank\" rel=\"noreferrer noopener\">command injection<\/a> bug tied to the earlier AyySSHush campaign, suggesting possible actor overlap. Seven IPs show dual compromise, hinting at coordinated efforts.<\/p>\n\n\n\n<p>STRIKE assesses low-to-moderate confidence that China Nexus actors drive WrtHug, mirroring tactics in ORBs like LapDogs and PolarEdge. The focus on Taiwan and router persistence via SSH backdoors points to espionage infrastructure building.<\/p>\n\n\n\n<p>This fits a trend of state-sponsored router hijacks, evolving from brute-force to multi-stage infections.<\/p>\n\n\n\n<p>Targeted models include RT-AC1200HP, GT-AC5300, and DSL-AC68U, often in homes or small offices. While post-exploitation details remain unclear, the setup enables proxying C2 traffic and data exfiltration.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"indicators-of-compromise\"><strong>Indicators of Compromise<\/strong><\/h2>\n\n\n\n<p>Monitoring for these IOCs can help detect infections:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Indicator Type<\/th><th>Value<\/th><th>Details<\/th><\/tr><\/thead><tbody><tr><td>SHA-1<\/td><td>1894a6800dff523894eba7f31cea8d05d51032b4<\/td><td>WrtHug TLS certificate thumbprint<\/td><\/tr><tr><td>IPv4<\/td><td>46[.]132.187.85<\/td><td>Dual-compromised (WrtHug\/AyySSHush)<\/td><\/tr><tr><td>IPv4<\/td><td>46[.]132.187.24<\/td><td>Dual-compromised (WrtHug\/AyySSHush)<\/td><\/tr><tr><td>IPv4<\/td><td>221[.]43.126.86<\/td><td>Dual-compromised (WrtHug\/AyySSHush)<\/td><\/tr><tr><td>IPv4<\/td><td>122[.]100.210.209<\/td><td>Dual-compromised (WrtHug\/AyySSHush)<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Additional IPs: 59.26.66[.]44, 83.188.236[.]86, 195.234.71[.]218<\/p>\n\n\n\n<p>ASUS urges firmware updates and disabling unused features like AiCloud on supported devices. For EoL models, replacement is recommended, alongside network segmentation and TLS certificate monitoring.<\/p>\n\n\n\n<p>Organizations should scan for the IOC certificate and apply CISA&#8217;s known exploited catalog patches.<\/p>\n\n\n\n<p>As router attacks escalate in 2025, this incident highlights the need for vigilant SOHO security to thwart nation-state probing. SecurityScorecard calls for industry collaboration to counter such calculated threats.<\/p>\n\n\n\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A sophisticated cyber campaign known as Operation WrtHug has hijacked tens of thousands of ASUS WRT routers globally, turning them into potential espionage tools for suspected China-linked hackers. SecurityScorecard&#8217;s STRIKE team, in collaboration with ASUS, revealed the operation on November 18, 2025, highlighting how attackers exploited outdated firmware to build a stealthy network infrastructure. This [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":133827,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgKvUnpVSGKI6N4DQJRUuGlspeO2eH9iD8IZuLmo2YYkyfRhg4xzNpKwjFzz57O_huc5o00gh6B0cq5A3FQ_4XCIsawjS8vSrPcmVVbi_fdUk9Lx2MZifyaivGqYETCeFQr4gkNThQq02Mi9cx5DcA14LWotpPbeNE-t1c8NxxsqXxJFlysG48pBDrKnjPB\/s16000\/Hacking%20Operation%20WrtHug%20Asus%20Routers.webp","fifu_image_alt":"WrtHug ASUS Routers","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[10,11,2737],"tags":[149,151,416],"class_list":{"0":"post-133823","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-cyber-security","8":"category-cyber-security-news","9":"category-vulnerability-news","10":"tag-cyber-security","11":"tag-cyber-security-news","12":"tag-vulnerability"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.7.1 (Yoast SEO v25.7) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Massive Hacking Operation WrtHug Compromises Thousands of ASUS Routers Worldwide<\/title>\n<meta name=\"description\" content=\"A sophisticated cyber campaign known as Operation WrtHug has hijacked tens of thousands of ASUS WRT routers globally, turning them into potential espionage tools for suspected China-linked hackers.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cybersecuritynews.com\/wrthug-asus-routers\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Massive Hacking Operation WrtHug Compromises Thousands of ASUS Routers Worldwide\" \/>\n<meta property=\"og:description\" content=\"A sophisticated cyber campaign known as Operation WrtHug has hijacked tens of thousands of ASUS WRT routers globally, turning them into potential espionage tools for suspected China-linked hackers.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cybersecuritynews.com\/wrthug-asus-routers\/\" \/>\n<meta property=\"og:site_name\" content=\"Cyber Security News\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hackingtutorialsandnews\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/guruba008\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-19T15:58:56+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-11-19T16:01:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgKvUnpVSGKI6N4DQJRUuGlspeO2eH9iD8IZuLmo2YYkyfRhg4xzNpKwjFzz57O_huc5o00gh6B0cq5A3FQ_4XCIsawjS8vSrPcmVVbi_fdUk9Lx2MZifyaivGqYETCeFQr4gkNThQq02Mi9cx5DcA14LWotpPbeNE-t1c8NxxsqXxJFlysG48pBDrKnjPB\/s16000\/Hacking%20Operation%20WrtHug%20Asus%20Routers.webp\" \/><meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgKvUnpVSGKI6N4DQJRUuGlspeO2eH9iD8IZuLmo2YYkyfRhg4xzNpKwjFzz57O_huc5o00gh6B0cq5A3FQ_4XCIsawjS8vSrPcmVVbi_fdUk9Lx2MZifyaivGqYETCeFQr4gkNThQq02Mi9cx5DcA14LWotpPbeNE-t1c8NxxsqXxJFlysG48pBDrKnjPB\/s16000\/Hacking%20Operation%20WrtHug%20Asus%20Routers.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Guru Baran\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgKvUnpVSGKI6N4DQJRUuGlspeO2eH9iD8IZuLmo2YYkyfRhg4xzNpKwjFzz57O_huc5o00gh6B0cq5A3FQ_4XCIsawjS8vSrPcmVVbi_fdUk9Lx2MZifyaivGqYETCeFQr4gkNThQq02Mi9cx5DcA14LWotpPbeNE-t1c8NxxsqXxJFlysG48pBDrKnjPB\/s16000\/Hacking%20Operation%20WrtHug%20Asus%20Routers.webp\" \/>\n<meta name=\"twitter:creator\" content=\"@guruba008\" \/>\n<meta name=\"twitter:site\" content=\"@The_Cyber_News\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Guru Baran\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Massive Hacking Operation WrtHug Compromises Thousands of ASUS Routers Worldwide","description":"A sophisticated cyber campaign known as Operation WrtHug has hijacked tens of thousands of ASUS WRT routers globally, turning them into potential espionage tools for suspected China-linked hackers.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cybersecuritynews.com\/wrthug-asus-routers\/","og_locale":"en_US","og_type":"article","og_title":"Massive Hacking Operation WrtHug Compromises Thousands of ASUS Routers Worldwide","og_description":"A sophisticated cyber campaign known as Operation WrtHug has hijacked tens of thousands of ASUS WRT routers globally, turning them into potential espionage tools for suspected China-linked hackers.","og_url":"https:\/\/cybersecuritynews.com\/wrthug-asus-routers\/","og_site_name":"Cyber Security News","article_publisher":"https:\/\/www.facebook.com\/Hackingtutorialsandnews","article_author":"https:\/\/www.facebook.com\/guruba008","article_published_time":"2025-11-19T15:58:56+00:00","article_modified_time":"2025-11-19T16:01:25+00:00","og_image":[{"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgKvUnpVSGKI6N4DQJRUuGlspeO2eH9iD8IZuLmo2YYkyfRhg4xzNpKwjFzz57O_huc5o00gh6B0cq5A3FQ_4XCIsawjS8vSrPcmVVbi_fdUk9Lx2MZifyaivGqYETCeFQr4gkNThQq02Mi9cx5DcA14LWotpPbeNE-t1c8NxxsqXxJFlysG48pBDrKnjPB\/s16000\/Hacking%20Operation%20WrtHug%20Asus%20Routers.webp","type":"","width":"","height":""},{"width":1600,"height":900,"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgKvUnpVSGKI6N4DQJRUuGlspeO2eH9iD8IZuLmo2YYkyfRhg4xzNpKwjFzz57O_huc5o00gh6B0cq5A3FQ_4XCIsawjS8vSrPcmVVbi_fdUk9Lx2MZifyaivGqYETCeFQr4gkNThQq02Mi9cx5DcA14LWotpPbeNE-t1c8NxxsqXxJFlysG48pBDrKnjPB\/s16000\/Hacking%20Operation%20WrtHug%20Asus%20Routers.webp","type":"image\/jpeg"}],"author":"Guru Baran","twitter_card":"summary_large_image","twitter_image":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgKvUnpVSGKI6N4DQJRUuGlspeO2eH9iD8IZuLmo2YYkyfRhg4xzNpKwjFzz57O_huc5o00gh6B0cq5A3FQ_4XCIsawjS8vSrPcmVVbi_fdUk9Lx2MZifyaivGqYETCeFQr4gkNThQq02Mi9cx5DcA14LWotpPbeNE-t1c8NxxsqXxJFlysG48pBDrKnjPB\/s16000\/Hacking%20Operation%20WrtHug%20Asus%20Routers.webp","twitter_creator":"@guruba008","twitter_site":"@The_Cyber_News","twitter_misc":{"Written by":"Guru Baran","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cybersecuritynews.com\/wrthug-asus-routers\/#article","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/wrthug-asus-routers\/"},"author":{"name":"Guru Baran","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/f7f138f8fd41a61bb60151da47730026"},"headline":"Massive Hacking Operation WrtHug Compromises Thousands of ASUS Routers Worldwide","datePublished":"2025-11-19T15:58:56+00:00","dateModified":"2025-11-19T16:01:25+00:00","mainEntityOfPage":{"@id":"https:\/\/cybersecuritynews.com\/wrthug-asus-routers\/"},"wordCount":632,"publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"image":{"@id":"https:\/\/cybersecuritynews.com\/wrthug-asus-routers\/#primaryimage"},"thumbnailUrl":"https:\/\/i3.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgKvUnpVSGKI6N4DQJRUuGlspeO2eH9iD8IZuLmo2YYkyfRhg4xzNpKwjFzz57O_huc5o00gh6B0cq5A3FQ_4XCIsawjS8vSrPcmVVbi_fdUk9Lx2MZifyaivGqYETCeFQr4gkNThQq02Mi9cx5DcA14LWotpPbeNE-t1c8NxxsqXxJFlysG48pBDrKnjPB\/s16000\/Hacking%20Operation%20WrtHug%20Asus%20Routers.webp?w=1600&resize=1600,900&ssl=1","keywords":["cyber security","cyber security news","vulnerability"],"articleSection":["Cyber Security","Cyber Security News","Vulnerability News"],"inLanguage":"en-US","copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/cybersecuritynews.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cybersecuritynews.com\/wrthug-asus-routers\/","url":"https:\/\/cybersecuritynews.com\/wrthug-asus-routers\/","name":"Massive Hacking Operation WrtHug Compromises Thousands of ASUS Routers Worldwide","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cybersecuritynews.com\/wrthug-asus-routers\/#primaryimage"},"image":{"@id":"https:\/\/cybersecuritynews.com\/wrthug-asus-routers\/#primaryimage"},"thumbnailUrl":"https:\/\/i3.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgKvUnpVSGKI6N4DQJRUuGlspeO2eH9iD8IZuLmo2YYkyfRhg4xzNpKwjFzz57O_huc5o00gh6B0cq5A3FQ_4XCIsawjS8vSrPcmVVbi_fdUk9Lx2MZifyaivGqYETCeFQr4gkNThQq02Mi9cx5DcA14LWotpPbeNE-t1c8NxxsqXxJFlysG48pBDrKnjPB\/s16000\/Hacking%20Operation%20WrtHug%20Asus%20Routers.webp?w=1600&resize=1600,900&ssl=1","datePublished":"2025-11-19T15:58:56+00:00","dateModified":"2025-11-19T16:01:25+00:00","description":"A sophisticated cyber campaign known as Operation WrtHug has hijacked tens of thousands of ASUS WRT routers globally, turning them into potential espionage tools for suspected China-linked hackers.","breadcrumb":{"@id":"https:\/\/cybersecuritynews.com\/wrthug-asus-routers\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cybersecuritynews.com\/wrthug-asus-routers\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/wrthug-asus-routers\/#primaryimage","url":"https:\/\/i3.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgKvUnpVSGKI6N4DQJRUuGlspeO2eH9iD8IZuLmo2YYkyfRhg4xzNpKwjFzz57O_huc5o00gh6B0cq5A3FQ_4XCIsawjS8vSrPcmVVbi_fdUk9Lx2MZifyaivGqYETCeFQr4gkNThQq02Mi9cx5DcA14LWotpPbeNE-t1c8NxxsqXxJFlysG48pBDrKnjPB\/s16000\/Hacking%20Operation%20WrtHug%20Asus%20Routers.webp?w=1600&resize=1600,900&ssl=1","contentUrl":"https:\/\/i3.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgKvUnpVSGKI6N4DQJRUuGlspeO2eH9iD8IZuLmo2YYkyfRhg4xzNpKwjFzz57O_huc5o00gh6B0cq5A3FQ_4XCIsawjS8vSrPcmVVbi_fdUk9Lx2MZifyaivGqYETCeFQr4gkNThQq02Mi9cx5DcA14LWotpPbeNE-t1c8NxxsqXxJFlysG48pBDrKnjPB\/s16000\/Hacking%20Operation%20WrtHug%20Asus%20Routers.webp?w=1600&resize=1600,900&ssl=1","width":"1600","height":"900","caption":"WrtHug ASUS Routers"},{"@type":"BreadcrumbList","@id":"https:\/\/cybersecuritynews.com\/wrthug-asus-routers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cybersecuritynews.com\/"},{"@type":"ListItem","position":2,"name":"Massive Hacking Operation WrtHug Compromises Thousands of ASUS Routers Worldwide"}]},{"@type":"WebSite","@id":"https:\/\/cybersecuritynews.com\/#website","url":"https:\/\/cybersecuritynews.com\/","name":"Cyber Security News","description":"World&#039;s #1 Premier Cybersecurity and Hacking News Portal","publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cybersecuritynews.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/cybersecuritynews.com\/#organization","name":"Cyber Security News","url":"https:\/\/cybersecuritynews.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/","url":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","contentUrl":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","width":200,"height":200,"caption":"Cyber Security News"},"image":{"@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hackingtutorialsandnews","https:\/\/x.com\/The_Cyber_News","https:\/\/www.linkedin.com\/company\/cybersecurity-news\/"]},{"@type":"Person","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/f7f138f8fd41a61bb60151da47730026","name":"Guru Baran","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/72f86da0bb72b6886d25f0ef0c881daba3a98356bc44f916f8d3a62c9e856579?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/72f86da0bb72b6886d25f0ef0c881daba3a98356bc44f916f8d3a62c9e856579?s=96&d=mm&r=g","caption":"Guru Baran"},"description":"Gurubaran is the Co-Founder and Editor-in-Chief of CyberSecurityNews.com, specializing in vulnerability analysis, malware research, ransomware, and computer forensics.","sameAs":["https:\/\/cybersecuritynews.com","https:\/\/www.facebook.com\/guruba008","https:\/\/www.linkedin.com\/in\/gurubaran-cyberwrites\/","https:\/\/x.com\/guruba008"],"url":"https:\/\/cybersecuritynews.com\/author\/guru\/"}]}},"jetpack_featured_media_url":"https:\/\/i3.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgKvUnpVSGKI6N4DQJRUuGlspeO2eH9iD8IZuLmo2YYkyfRhg4xzNpKwjFzz57O_huc5o00gh6B0cq5A3FQ_4XCIsawjS8vSrPcmVVbi_fdUk9Lx2MZifyaivGqYETCeFQr4gkNThQq02Mi9cx5DcA14LWotpPbeNE-t1c8NxxsqXxJFlysG48pBDrKnjPB\/s16000\/Hacking%20Operation%20WrtHug%20Asus%20Routers.webp?w=1600&resize=1600,900&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/133823","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/comments?post=133823"}],"version-history":[{"count":1,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/133823\/revisions"}],"predecessor-version":[{"id":133825,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/133823\/revisions\/133825"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media\/133827"}],"wp:attachment":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media?parent=133823"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/categories?post=133823"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/tags?post=133823"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}