Close Menu

    Subscribe to Updates

    Get the latest tech news from Tallwire.

    What's Hot

    AI Productivity Gains Concentrated Among High-Skilled Workers, Study Finds

    February 28, 2026

    Single Compromised Account Exposes 1.2 Million French Banking Records

    February 28, 2026

    Sam Altman Says ‘AI Washing’ Is Being Used to Mask Corporate Layoffs

    February 28, 2026
    Facebook X (Twitter) Instagram
    • Tech
    • AI
    • Get In Touch
    Facebook X (Twitter) LinkedIn
    TallwireTallwire
    • Tech

      Taara Beam Launch Brings 25Gbps Optical Wireless Networks to Cities

      February 27, 2026

      Global Memory Shortage Set to Push Up Prices on Phones, Laptops, and More

      February 27, 2026

      OpenAI’s Stargate Data Center Ambitions Hit Major Roadblocks

      February 27, 2026

      Large Hadron Collider Enters Third Shutdown For Major Upgrade

      February 26, 2026

      Stellantis Faces Massive Losses and Strategic Shift After Misjudging EV Market Demand

      February 26, 2026
    • AI

      AI Productivity Gains Concentrated Among High-Skilled Workers, Study Finds

      February 28, 2026

      X to Let Users Mark Posts ‘Made With AI’ as Platform Eyes Voluntary Disclosure Feature

      February 27, 2026

      Uber Rolls Out “Uber Autonomous Solutions” To Support Third-Party Robotaxi Partners

      February 27, 2026

      Global Memory Shortage Set to Push Up Prices on Phones, Laptops, and More

      February 27, 2026

      OpenAI’s Stargate Data Center Ambitions Hit Major Roadblocks

      February 27, 2026
    • Security

      Single Compromised Account Exposes 1.2 Million French Banking Records

      February 28, 2026

      PayPal Data Breach Exposed Customer Personal Information For Months

      February 27, 2026

      Discord Ends Persona Age Verification Trial Amid Privacy Backlash

      February 27, 2026

      FBI Issues Alert on Outdated Wi-Fi Routers Vulnerable to Cyber Attacks

      February 25, 2026

      Wikipedia Blacklists Archive.Today After DDoS Abuse And Content Manipulation

      February 24, 2026
    • Health

      Social Media Addiction Trial Draws Grieving Parents Seeking Accountability From Tech Platforms

      February 19, 2026

      Portugal’s Parliament OKs Law to Restrict Children’s Social Media Access With Parental Consent

      February 18, 2026

      Parents Paint 108 Names, Demand Snapchat Reform After Deadly Fentanyl Claims

      February 18, 2026

      UK Kids Turning to AI Chatbots and Acting on Advice at Alarming Rates

      February 16, 2026

      Landmark California Trial Sees YouTube Defend Itself, Rejects ‘Social Media’ and Addiction Claims

      February 16, 2026
    • Science

      Microsoft Claims 100 Percent Renewable Energy Match Across Global Electricity Use

      February 28, 2026

      Taara Beam Launch Brings 25Gbps Optical Wireless Networks to Cities

      February 27, 2026

      Large Hadron Collider Enters Third Shutdown For Major Upgrade

      February 26, 2026

      Google Phases Out Android’s Built-In Weather App, Replacing It With Search-Based Forecasts

      February 25, 2026

      Microsoft’s Breakthrough Suggests Data Could Be Preserved for 10,000 Years on Glass

      February 24, 2026
    • Tech

      Sam Altman Says ‘AI Washing’ Is Being Used to Mask Corporate Layoffs

      February 28, 2026

      Zuckerberg Testifies In Landmark Trial Over Alleged Teen Social Media Harms

      February 23, 2026

      Gay Tech Networks Under Spotlight In Silicon Valley Culture Debate

      February 23, 2026

      Google Co-Founder’s Epstein Contacts Reignite Scrutiny of Elite Tech Circles

      February 7, 2026

      Bill Gates Denies “Absolutely Absurd” Claims in Newly Released Epstein Files

      February 6, 2026
    TallwireTallwire
    Home»Tech»State-Sponsored Spy Net Hijacks Thousands of Home Routers
    Tech

    State-Sponsored Spy Net Hijacks Thousands of Home Routers

    Updated:February 21, 20264 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    State-Sponsored Spy Net Hijacks Thousands of Home Routers
    State-Sponsored Spy Net Hijacks Thousands of Home Routers
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A newly exposed cyber espionage operation dubbed Operation WrtHug is targeting tens of thousands of outdated routers made by ASUS, primarily consumer WRT models, converting them into stealthy relay networks for suspected Chinese-state actors. According to cybersecurity firm SecurityScorecard’s STRIKE team, the campaign forces itself onto end-of-life routers via proprietary vulnerabilities in ASUS’s AiCloud service and related firmware flaws, granting near-root access and embedding persistent backdoors. The impact spans around 50,000 compromised devices worldwide, with major concentrations in Taiwan, Southeast Asia and pockets in the U.S. and Russia, though mainland China appears largely unaffected. Analysts warn this is not a simple botnet for spam or DDoS, but an infrastructure play—building a covert “infrastructure of convenience” inside consumer networks that can support long-range espionage. The campaign’s sophistication and target profile signal a heightened risk to homes and small-office routers, which traditionally receive fewer security updates and travel through network environments blind-spot.

    Sources: InfoSecurity Magazine, TechRadar

    Key Takeaways

    – Home and small-office routers, especially end-of-life models, are increasingly being repurposed by nation-state actors to provide infrastructure support for espionage rather than direct attack payloads.

    – The scale of the compromise (≈50,000 devices) and the method (leveraging proprietary apps, n-day vulnerabilities and long-term persistence) suggests this is an intelligence-gathering play rather than mere cybercrime for profit.

    – Users and network defenders often overlook the security hygiene of routers and “set-and-forget” network gear—this campaign underscores how legacy firmware, enabled remote management, and default credentials create persistent back-doors into larger infrastructure.

    In-Depth

    The discovery of Operation WrtHug signals a significant escalation in how state-sponsored cyber espionage is evolving—not by focusing solely on high-value corporate or governmental servers, but by quietly embedding itself in the vast network of home and small-office routers. The primary targets here: end-of-life ASUS WRT routers supporting the AiCloud service, which the threat actors exploit via n-day and proprietary vulnerabilities to gain high-level privileges, install custom SSH keys, disable logging, and persist across reboots and firmware updates. According to SecurityScorecard’s STRIKE threat intelligence team, the attackers appear confident and patient—using these compromised routers as operational relay boxes (ORBs) to route communication, mask provenance, and support long-term spying infrastructure.

    The geographic distribution is telling: while compromised routers are found globally, the densest clusters sit in Taiwan and Southeast Asia, with additional victims in the U.S. and Russia—but nearly no identified devices in mainland China. This suggests deliberate avoidance of domestic attribution for the perpetrating actor, aligning with intelligence-grade operations rather than opportunistic hacking. The precision and stealth of the campaign further support the idea that this is not simply a cybercrime ring seeking rent, but a strategically controlled espionage platform.

    From a practical standpoint, this incident offers troubling reminders: most consumers and small businesses treat a router like a dime-store appliance—plug it in, maybe change the password once, ignore it forever. Meanwhile, threat actors see it as one of the most under-defended front-lines of the networked world. Firmware updates usually lag behind routers; remote-management features are often left enabled; default credentials or predictable passwords persist; logging is disabled; and rarely is there any form of detection or monitoring. This combination makes routers the perfect staging platforms for intelligence-gathering networks or proxy services for more sensitive internal network operations.

    For professionals and private users alike, the steps to reduce exposure are straightforward yet often overlooked: replace or update unsupported routers, disable remote administration unless strictly needed, enforce strong admin credentials, keep firmware current, and monitor outbound traffic from your network for unusual patterns. On the institutional level, internet-service providers and network operators should re-evaluate the implicit trust placed in consumer‐grade devices on their networks—particularly given their increasing use as invisible launch pads for state-level operations.

    In a broader sense, the rise of campaigns like Operation WrtHug reflects a strategic shift: rather than seeking the flash to crash major services, threat actors are quietly embedding themselves in the infrastructure we assume is “safe”—home routers, WiFi networks, peripheral devices—then using that foothold for espionage, masking, and persistence. For defenders, the warning is clear: securing endpoints is not just about the laptop or the server—it’s about the invisible plumbing of the network, beginning at the router.

    Taiwan Tech
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleState-Backed Hackers Breach U.S. Telecom Infrastructure Supplier After Months Undetected
    Next Article Streaming Devices Quietly Tracking Your Viewing Habits Without Consent

    Related Posts

    Taara Beam Launch Brings 25Gbps Optical Wireless Networks to Cities

    February 27, 2026

    Global Memory Shortage Set to Push Up Prices on Phones, Laptops, and More

    February 27, 2026

    OpenAI’s Stargate Data Center Ambitions Hit Major Roadblocks

    February 27, 2026

    Large Hadron Collider Enters Third Shutdown For Major Upgrade

    February 26, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Taara Beam Launch Brings 25Gbps Optical Wireless Networks to Cities

    February 27, 2026

    Global Memory Shortage Set to Push Up Prices on Phones, Laptops, and More

    February 27, 2026

    OpenAI’s Stargate Data Center Ambitions Hit Major Roadblocks

    February 27, 2026

    Large Hadron Collider Enters Third Shutdown For Major Upgrade

    February 26, 2026
    Popular Topics
    Tesla Cybertruck Ransomware UAE Tech SpaceX Tesla Samsung Sundar Pichai trending Robotics Satya Nadella Qualcomm Taiwan Tech Startup spotlight Quantum computing Series A Sam Altman Tim Cook Series B picks
    Major Tech Companies
    • Apple News
    • Google News
    • Meta News
    • Microsoft News
    • Amazon News
    • Samsung News
    • Nvidia News
    • OpenAI News
    • Tesla News
    • AMD News
    • Anthropic News
    • Elbit News
    AI & Emerging Tech
    • AI Regulation News
    • AI Safety News
    • Quantum Computing News
    • Robotics News
    Key People
    • Sam Altman News
    • Jensen Huang News
    • Elon Musk News
    • Mark Zuckerberg News
    • Sundar Pichai News
    • Tim Cook News
    • Satya Nadella News
    • Mustafa Suleyman News
    Global Tech & Policy
    • Israel Tech News
    • India Tech News
    • Taiwan Tech News
    • UAE Tech News
    Startups & Emerging Tech
    • Series A News
    • Series B News
    • Startup News
    Tallwire
    Facebook X (Twitter) LinkedIn Threads Instagram RSS
    • Tech
    • Entertainment
    • Business
    • Government
    • Academia
    • Transportation
    • Legal
    • Press Kit
    © 2026 Tallwire. Optimized by ARMOUR Digital Marketing Agency.

    Type above and press Enter to search. Press Esc to cancel.