Cyberattacks hit fast today and sometimes slip under the radar until the damage is widespread. Operation WrtHug is a perfect example. This global campaign has hijacked thousands of outdated ASUS routers using a cluster of security flaws. Many of these routers sit in homes and small offices where people never think twice about firmware updates.
Relevant Source (SecurityScorecard): Operation WrtHug, The Global Espionage Campaign Hiding In Your Home Router
This report details how Operation WrtHug compromises end-of-life ASUS WRT routers worldwide using six known vulnerabilities, confirms the scale of the campaign, and explains the 100-year TLS certificate indicator that your article discusses.
Quick Facts
- Operation WrtHug compromised about fifty thousand ASUS routers.
- Attackers used six known vulnerabilities to take control of outdated models.
- Most infections hit Taiwan and Southeast Asia with some in Europe and the United States.
- A unique one hundred year TLS certificate helps confirm compromised devices.
- Firmware updates or device replacement are the best defenses.
What Operation WrtHug Is And How It Started
Operation WrtHug is a coordinated attack that targets ASUS WRT routers that reached end of life or have not been updated. These devices run on older firmware that still contains serious security flaws. Attackers exploited six known vulnerabilities that let them execute commands on the router without permission. They focused on AC series and AX series models that run ASUS AiCloud features.
Attackers scanned the internet looking for exposed routers and found roughly fifty thousand unique IP addresses tied to infected devices. Many of these infections clustered in Taiwan with others spread across Southeast Asia, Russia, Europe, and the United States. Researchers found no infections inside China which raised questions about who is behind the campaign.
Old routers with neglected updates turn into open doors for attackers. Many owners never notice anything wrong because the internet still works.
Relevant Source (SecurityScorecard): SecurityScorecard Exposes Global ASUS Router Hijack “WrtHug” With Suspected China Links
This article summarizes SecurityScorecard’s STRIKE findings on Operation WrtHug, including its focus on end-of-life ASUS models, geographic clustering of infections, and use of a unique one hundred year TLS certificate as a key indicator of compromise.
Why Operation WrtHug Matters To Everyday Users
People rely on routers to protect home networks without thinking about it. When a router is compromised an attacker can intercept traffic, hide malicious activity, or use the device as a stepping stone to other targets. Researchers believe these hijacked routers may be acting as stealth relay points in larger hacking operations.
A compromised router can:
- Route harmful traffic without the user knowing.
- Expose connections inside the home or business network.
- Allow attackers to mask their command systems.
- Open the door to future exploits that build on the same weaknesses.
Users should care about router security because these devices sit between private networks and the entire internet. Weak spots here create weak spots everywhere.
Relevant Source (CISA): Home Network Security
This guidance explains how compromised home routers can expose entire networks and gives practical steps for securing devices that sit between users and the internet.
Relevant Source (FBI / IC3): Foreign Cyber Actors Target Home And Office Routers And Networked Devices Worldwide
This public service announcement describes how router malware like VPNFilter can intercept traffic, disrupt service, and turn small office and home routers into platforms for larger cyber operations.

How The Attacks Work
WrtHug uses known security flaws that let attackers force the router to run commands even though they are not authorized. One of the most serious issues, CVE-2025-2492, bypasses authentication controls when AiCloud is enabled. That means an attacker can send a crafted request and gain access without logging in.
Once inside, attackers replace the router’s normal certificate with a strange self-signed certificate that lasts one hundred years. This certificate stood out because ASUS normally issues ten year certificates. That difference helped researchers identify infected devices quickly.
Attackers do not fix or upgrade the firmware after taking over. This leaves the router vulnerable to any other hacker who finds the same flaws. The device becomes a shared playground that anyone can exploit until the owner updates or replaces the hardware.
Attackers succeeded because the routers were old and never patched. Outdated firmware is like leaving the front door unlocked for years.
Relevant Source (NVD / NIST): CVE-2025-2492 Detail
This CVE entry documents the improper authentication control in ASUS AiCloud that allows crafted remote requests to execute functions without authorization, matching how WrtHug gains access.
Relevant Source (The Hacker News): ASUS Confirms Critical Flaw In AiCloud Routers; Users Urged To Update Firmware
This report explains the critical AiCloud vulnerability exploited for remote code execution on ASUS routers and reinforces the role of outdated firmware and unpatched flaws in attacks like WrtHug.
What Users Should Do Now To Stay Safe
People who own older ASUS routers should act soon. These attacks spread because many devices stayed unpatched long after updates were available. A few steps help reduce the risk right away.
Action Steps
- Update firmware to the latest ASUS release.
- Disable remote access features if the router is no longer supported.
- Replace end-of-life devices with supported models.
- Reset the router and check for unusual certificates in AiCloud settings.
- Avoid leaving AiCloud enabled unless it is required.
Users should take these steps even if the router seems to be working normally. Silent infections rarely show symptoms until attackers use the device for something worse.
Relevant Source (CISA): Securing Your Home Network: Module 5 – Check Your Router Firmware
This item outlines the need to update home router firmware and disable outdated remote access features, aligning with the section’s advice to update devices and disable remote access.
The Bigger Picture For Router Security
Router attacks are becoming more common because home networks often use outdated hardware. Threat actors treat these devices as entry points for proxy networks or hidden relay channels. Campaigns like AyySSHush and WrtHug show how quickly attackers adapt old vulnerabilities into new operations.
Security researchers expect more flaws to appear as devices age. ASUS recently fixed another authentication bypass, CVE-2025-59367, and attackers could add it to their toolkit soon. This trend shows why regular updates and hardware refresh cycles matter. People need to think of routers the same way they think of phones or computers.
Old routers are a growing liability for everyone connected to modern networks.
Relevant Source (CISA / FBI): Security Design Improvements For SOHO Device Manufacturers
This joint alert explains how state actors abuse home and small office routers as proxy nodes and stresses that outdated, unpatched network devices create long-term systemic risk, echoing the trend described in this section.
Relevant Source (CISA): PRC State-Sponsored Actors Compromise And Maintain Persistent Access To U.S. Critical Infrastructure
This advisory details how Volt Typhoon and similar groups rely on compromised SOHO routers as stealth relay infrastructure, reinforcing the point that aging routers are being folded into larger, long-running proxy and botnet campaigns.
Final Thoughts
Operation WrtHug proves how dangerous neglected devices can become. Attackers took advantage of six known security flaws and turned outdated ASUS routers into global relay nodes. Users who still rely on older models should update, disable remote features, or replace their routers. Staying ahead of threats starts with keeping the hardware that protects the network in good shape. Small steps today can prevent bigger problems tomorrow.
FAQ
What is Operation WrtHug?
It is a global hacking campaign that compromises outdated ASUS routers using known vulnerabilities.
Which ASUS models are affected?
Common targets include AC and AX series devices such as RT-AC1200HP, RT-AC1300UHP, GT-AC5300, and more.
How can users tell if their router is infected?
One sign is a self-signed one hundred year TLS certificate inside the AiCloud settings.
Does updating the firmware stop the attack?
Yes. ASUS has released patches for all six exploited flaws.
Should outdated routers be replaced?
Yes. End-of-life devices no longer receive security updates and remain vulnerable.
How JENI Strengthens Everyday Device Security
Modern threats move fast, and most users do not have time to dig through settings or track hidden vulnerabilities across their devices. JENI helps close that gap by keeping systems clean, efficient, and less exposed to the kinds of weaknesses attackers commonly exploit. A smoother system reduces the chance that outdated components or ignored warnings leave an opening.
What JENI Delivers Behind The Scenes
- Flags outdated software that increases exposure to security risks.
- Improves system stability so devices run clean without clutter that hides warning signs.
- Helps users maintain a healthier environment that supports stronger network defenses.
A strong router is important, but a well-maintained computer protects the rest of the chain. JENI supports that goal by reducing unnecessary strain, closing performance gaps, and helping users stay ahead of avoidable issues. Cleaner systems respond faster which makes security tools work better. Security begins with a device that runs the way it should, and JENI helps keep it that way.

