Kaspersky: ASUS pushed a malicious backdoor to ~500K Windows machines for at least five months last year, after its live software update tool was compromised
Earlier today, Motherboard published … Lily Hay Newman / Wired : HACK BRIEF: HOW TO CHECK YOUR COMPUTER FOR ASUS UPDATE MALWARE Vibhuti Sharma / Reuters : Asus implements fix for malware attack Kaspersky Lab Blog : ShadowHammer: Malicious updates for ASUS laptops Sergiu Gatlan / BleepingComputer : ASUS Admits Its Live Update Utility Was Backdoored by APT Group Sean Michael Kerner / eWeek : Asus Confirms Attack Against Update Tool That Exposed Users to Risk Catalin Cimpanu / ZDNet : ASUS releases fix for Live Update tool abused in ShadowHammer attack Jon Fingas / Engadget : ASUS releases fix for ShadowHammer malware attack Lucian Constantin / CSO : ASUS users fall victim to supply chain attack through backdoored update Roland Moore-Colyer / Inquirer : Asus software hijacked to spread malware to ‘millions’ of PC users Symantec : ASUS Software Updates Used for Supply Chain Attacks Fortune : Apple Announcements, Obamacare Gamble, Brexit Votes: CEO Daily for March 26, 2019 Trisha Jalan / MediaNama : Hackers attacked ASUS update server to install malicious backdoor on computers: Kaspersky Wirecutter : Lessons From the Asus Hack: How to Keep Your Computer Safe Mark Wyciślik-Wilson / BetaNews : ASUS Live Update Utility hacked to deliver ShadowHammer backdoor malware to a million systems Debby Wu / Bloomberg : Asus Hack May Have Infected More Than a Million PC Users Tweets: Kim Zetter / @kimzetter : ASUS, one of world's largest computer makers, installed backdoor on thousands of customer computers last yr after hackers compromised its software update tool. The file was signed w/ ASUS digital certificates to make it look like authentic software update. https://motherboard.vice.com/ ... Joseph Cox / @josephfcox : This is absolutely insane. Hackers broke into an update server for laptop maker ASUS. The hackers then used it to push malware that looked like a legitimate ASUS update to thousands of computers. A golden supply chain attack leveraging update mechanisms https://motherboard.vice.com/ ... pic.twitter.com/AbRMhgteiq Costin Raiu / @craiu : Asus Live Updater was used in a big supply chain attack we dubbed Operation #ShadowHammer. We estimate this may have affected over 1 million computer users between June and Nov 2018. https://motherboard.vice.com/ ... Kim Zetter / @kimzetter : .@ASUS has finally released statement. Says only small number of machines infected (researchers say 500k+); also says it's finally begun to notify customers (@kaspersky told them about prob in Jan.) They don't bother to thank Kaspersky at all in statement. http://www.asus.com/... http://twitter.com/... Kim Zetter / @kimzetter : “The researchers estimate half a million Windows machines received the malicious backdoor through the ASUS update server, although the attackers appear to have been targeting only about 600 of those systems. The malware searched for targeted systems thru their unique MAC address” Matt Blaze / @mattblaze : Oh man the ASUS thing. This is the worst kind of supply chain attack. It threatens to poison faith in the integrity of update mechanisms that have become essential for security today. But in spite of this one attack, you are still WAY better off keeping things updated. Really. Costin Raiu / @craiu : Our blogpost on Operation #ShadowHammer, with information about targets, geography of victims and IOCs: http://securelist.com/... http://twitter.com/... Selena / @selenalarson : Kaspersky found a trojanized ASUS utility that appeared legit, interestingly only targeted 600 MAC addresses out of 57K users who installed it. Plus: “We found out that the same techniques were used against software from three other vendors.” http://www.kaspersky.com/... @swiftonsecurity : Wow, hard-coded to only activate on ~600 MAC addresses attacker was after. Not sure attackers even knew they were ASUS laptops, this could be them casting a wide net? Backdoored software installed on a million systems. That's a pretty dedicated attacker. https://twitter.com/... Zack Whittaker / @zackwhittaker : Just in: Symantec data breaks out those affected by the Asus backdoor. “80 percent of victims were consumers and 20 percent were from organizations.” The attacker and their motivation is “unclear at this time.”
Context & Ripple Effects
Kaspersky's disclosure is the opening move in what became a multi-day arc: within days, ASUS confirmed the compromise and shipped a detection tool for affected machines, while separately a researcher warned the company about staff passwords published to public GitHub repos months earlier. The attack's design matters more than its scale — the backdoor sat inside a trusted vendor update channel but only activated on roughly 600 hard-coded MAC addresses.
That precision targeting reframes the incident from a mass-infection story into an intelligence operation riding on ASUS's own distribution infrastructure, which is why it has become a reference point for later vendor-channel compromises.
First-order effects
- Roughly 500,000 Windows users who ran ASUS Live Update received the trojanized installer for at least five months, though only the ~600 MAC-targeted machines were actually activated — most victims carried dormant malware without knowing it.
- ASUS is immediately forced into remediation mode: patching Live Update, publishing a serial-number/MAC lookup so customers can check exposure, and answering for how its signing pipeline was abused.
Second-order effects
- Every PC vendor's update utility now faces the same audit question — if ASUS's trusted channel went undetected for five months, rivals must prove their own signing and distribution pipelines weren't similarly compromised, shifting security budgets toward build-chain integrity.
- The MAC-address filtering shows attackers using vendor channels as a scalpel rather than a shotgun, pushing enterprises to treat OEM update traffic as untrusted until verified rather than implicitly safe.
Third-order effects
- If the pattern holds, vendor update infrastructure becomes a standing target for state-aligned groups, and the industry moves toward reproducible builds, hardened signing, and independent verification of update artifacts as baseline requirements rather than best practices.
- The 2025 GreyNoise botnet embedding a reboot-persistent SSH backdoor in ASUS routers shows the same thesis six years on: compromising the vendor's own maintenance path beats attacking endpoints one by one, making supply-chain defense a structural requirement across consumer hardware, not just PCs.
The trend: Software supply-chain attacks are migrating from opportunistic mass infection to precision operations hidden inside vendors' own trusted update channels, forcing hardware makers to treat their distribution pipelines as critical attack surface.