Thousands of ASUS routers have been hacked to create a major botnet by threat actors exploiting security vulnerabilities.The hackers gained initial access by exploiting poorly secured routers using brute force and authentication bypass methods.They abused a known command injection flaw (CVE-2023-39780) to establish persistent access and create a botnet.The attackers can maintain long-term access without dropping malware traces, with the number of compromised devices steadily increasing.