← Asustek Computer

2018–2019 ASUS (ShadowHammer) — trojanized Live Update supply-chain distribution; MAC-targeted second stage

2019 500.0K records affected Share on X

Data compromised

Primarily endpoint compromise and potential exfiltration channel to selected targets; not a single centralized customer database leak

Technical writeup

Operation ShadowHammer, publicized in 2019 following Kaspersky research summarized by CERT-EU, described trojanized ASUS Live Update packages digitally signed by ASUSTeK and served from legitimate ASUS update infrastructure between roughly June–November 2018, delivering a backdoor to on the order of hundreds of thousands of Windows systems while a hard-coded MAC-address list (hundreds of entries in analyzed samples) steered second-stage payloads to a small targeted set. ASUS ultimately released Live Update fixes and consumer diagnostic guidance.

Root cause

Supply-chain compromise of software update pipeline abusing trusted code-signing and automatic update trust

References