/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Kaspersky: ASUS pushed a malicious backdoor to ~500K Windows machines for at least five months last year, after its live software update tool was compromised

Earlier today, Motherboard published … Lily Hay Newman / Wired : HACK BRIEF: HOW TO CHECK YOUR COMPUTER FOR ASUS UPDATE MALWARE Vibhuti Sharma / Reuters : Asus implements fix for malware attack Kaspersky Lab Blog : ShadowHammer: Malicious updates for ASUS laptops Sergiu Gatlan / BleepingComputer : ASUS Admits Its Live Update Utility Was Backdoored by APT Group Sean Michael Kerner / eWeek : Asus Confirms Attack Against Update Tool That Exposed Users to Risk Catalin Cimpanu / ZDNet : ASUS releases fix for Live Update tool abused in ShadowHammer attack Jon Fingas / Engadget : ASUS releases fix for ShadowHammer malware attack Lucian Constantin / CSO : ASUS users fall victim to supply chain attack through backdoored update Roland Moore-Colyer / Inquirer : Asus software hijacked to spread malware to ‘millions’ of PC users Symantec : ASUS Software Updates Used for Supply Chain Attacks Fortune : Apple Announcements, Obamacare Gamble, Brexit Votes: CEO Daily for March 26, 2019 Trisha Jalan / MediaNama : Hackers attacked ASUS update server to install malicious backdoor on computers: Kaspersky Wirecutter : Lessons From the Asus Hack: How to Keep Your Computer Safe Mark Wyciślik-Wilson / BetaNews : ASUS Live Update Utility hacked to deliver ShadowHammer backdoor malware to a million systems Debby Wu / Bloomberg : Asus Hack May Have Infected More Than a Million PC Users Tweets: Kim Zetter / @kimzetter : ASUS, one of world's largest computer makers, installed backdoor on thousands of customer computers last yr after hackers compromised its software update tool. The file was signed w/ ASUS digital certificates to make it look like authentic software update. https://motherboard.vice.com/ ... Joseph Cox / @josephfcox : This is absolutely insane. Hackers broke into an update server for laptop maker ASUS. The hackers then used it to push malware that looked like a legitimate ASUS update to thousands of computers. A golden supply chain attack leveraging update mechanisms https://motherboard.vice.com/ ... pic.twitter.com/AbRMhgteiq Costin Raiu / @craiu : Asus Live Updater was used in a big supply chain attack we dubbed Operation #ShadowHammer. We estimate this may have affected over 1 million computer users between June and Nov 2018. https://motherboard.vice.com/ ... Kim Zetter / @kimzetter : .@ASUS has finally released statement. Says only small number of machines infected (researchers say 500k+); also says it's finally begun to notify customers (@kaspersky told them about prob in Jan.) They don't bother to thank Kaspersky at all in statement. http://www.asus.com/... http://twitter.com/... Kim Zetter / @kimzetter : “The researchers estimate half a million Windows machines received the malicious backdoor through the ASUS update server, although the attackers appear to have been targeting only about 600 of those systems. The malware searched for targeted systems thru their unique MAC address” Matt Blaze / @mattblaze : Oh man the ASUS thing. This is the worst kind of supply chain attack. It threatens to poison faith in the integrity of update mechanisms that have become essential for security today. But in spite of this one attack, you are still WAY better off keeping things updated. Really. Costin Raiu / @craiu : Our blogpost on Operation #ShadowHammer, with information about targets, geography of victims and IOCs: http://securelist.com/... http://twitter.com/... Selena / @selenalarson : Kaspersky found a trojanized ASUS utility that appeared legit, interestingly only targeted 600 MAC addresses out of 57K users who installed it. Plus: “We found out that the same techniques were used against software from three other vendors.” ‍ http://www.kaspersky.com/... @swiftonsecurity : Wow, hard-coded to only activate on ~600 MAC addresses attacker was after. Not sure attackers even knew they were ASUS laptops, this could be them casting a wide net? Backdoored software installed on a million systems. That's a pretty dedicated attacker. https://twitter.com/... Zack Whittaker / @zackwhittaker : Just in: Symantec data breaks out those affected by the Asus backdoor. “80 percent of victims were consumers and 20 percent were from organizations.” The attacker and their motivation is “unclear at this time.”

Motherboard Kim Zetter

Context & Ripple Effects

Kaspersky's disclosure is the opening move in what became a multi-day arc: within days, ASUS confirmed the compromise and shipped a detection tool for affected machines, while separately a researcher warned the company about staff passwords published to public GitHub repos months earlier. The attack's design matters more than its scale — the backdoor sat inside a trusted vendor update channel but only activated on roughly 600 hard-coded MAC addresses.

That precision targeting reframes the incident from a mass-infection story into an intelligence operation riding on ASUS's own distribution infrastructure, which is why it has become a reference point for later vendor-channel compromises.

First-order effects

  • Roughly 500,000 Windows users who ran ASUS Live Update received the trojanized installer for at least five months, though only the ~600 MAC-targeted machines were actually activated — most victims carried dormant malware without knowing it.
  • ASUS is immediately forced into remediation mode: patching Live Update, publishing a serial-number/MAC lookup so customers can check exposure, and answering for how its signing pipeline was abused.

Second-order effects

  • Every PC vendor's update utility now faces the same audit question — if ASUS's trusted channel went undetected for five months, rivals must prove their own signing and distribution pipelines weren't similarly compromised, shifting security budgets toward build-chain integrity.
  • The MAC-address filtering shows attackers using vendor channels as a scalpel rather than a shotgun, pushing enterprises to treat OEM update traffic as untrusted until verified rather than implicitly safe.

Third-order effects

  • If the pattern holds, vendor update infrastructure becomes a standing target for state-aligned groups, and the industry moves toward reproducible builds, hardened signing, and independent verification of update artifacts as baseline requirements rather than best practices.
  • The 2025 GreyNoise botnet embedding a reboot-persistent SSH backdoor in ASUS routers shows the same thesis six years on: compromising the vendor's own maintenance path beats attacking endpoints one by one, making supply-chain defense a structural requirement across consumer hardware, not just PCs.

The trend: Software supply-chain attacks are migrating from opportunistic mass infection to precision operations hidden inside vendors' own trusted update channels, forcing hardware makers to treat their distribution pipelines as critical attack surface.