ASUS Supply Chain Attack Delivers Backdoor to Over One Million Users
Unknown attackers compromise an ASUS update server to push a malicious backdoor through the ASUS Live Update Utility, aiming for 600 specific targets but ultimately affecting over a million users.
Unknown attackers compromise an ASUS update server and use it to distribute a malicious backdoor through the ASUS Live Update Utility. Kaspersky Lab researchers discover the malware in January 2019 and dub the campaign Operation ShadowHammer, noting that the attack unfolds between June and November 2018.
The attackers hardcode a list of over 600 specific MAC addresses into the trojanized updates to surgically target selected users. However, the malicious software ultimately reaches an estimated one million ASUS customers who automatically download the compromised BIOS, UEFI, and driver updates.
Kaspersky Lab creates a detection tool that allows users to check if they install the backdoored update by verifying their device's MAC address. The researchers notify ASUS of the compromise, but the company denies that attackers breach their core signing infrastructure, though evidence points to limited access to part of the signing system.