• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
iGuRu

iGuRu

Real-time Technology News. Opinions & Tweaks

  • / news
  • / infosec
  • / tools
  • / tweaks
  • / dummies
  • / opinions
  • / support
home / News / ASUS Live Update delivers malware for months

ASUS Live Update delivers malware for months

25/03/2019 20:48 by giorgos

ASUS Live Update Utility: A new advanced persistent threat (APT) detected by Kaspersky Lab in January of 2019 seems to run from June to November of 2018.

The threat is reported to have affected more than one million users who have downloaded data from ASUS Live Update Utility on their computers.asus logo - ASUS Live Update distributes malware for months

Kaspersky Lab's Global Research and Analysis team (GReAT) named this malicious Operation ShadowHammer, and as Kim Zetter initially mentioned, it led to downloading and installing data from a backdoored version of ASUS Live Update over 57.000 users using Kaspersky products (on ASUS computers of course).

While Kaspersky was able to stop most downloads from the trojanized ASUS Live Update, the company's research team estimates that over one million users are infected.ShadowHammer victims - ASUS Live Update distributes malware for months

According to GReAT:

ASUS Live Update is a utility that comes pre-installed on most ASUS computers. Used to automatically update certain items such as BIOS, UEFI, drivers and applications

And it continues:

According to Gartner, ASUS was the fifth largest computer company worldwide by 2017. This makes the company an extremely attractive target for APT teams that may want to take advantage of the range of their users.

According to GReAT, there were multiple versions of infected files in the ASUS Live Update that were shared, targeting "unknown groups of users identified by MAC addresses."

Attackers behind ShadowHammer have used a hardcoded list of MAC addresses to target the distribution of malicious software. Kaspersky managed to gather more than 600 MAC addresses from 200 malware samples used in this attack.

Kaspersky's researchers also found that the infected Live Update was digitally signed with "ASUSTeK Computer Inc." legal certificates. certificates hosted on the official (liveupdate01s.asus [.] com and liveupdate01.asus [.] com) update servers of ASUS.

If you're worried about your Asus computer, Kaspersky released one offline application and an online web checkerto check if your systems have been dropped by Operation ShadowHammer.

For testing, we compare your MAC address with the list of hardcoded addresses we discovered in malware.

___________________

  • Windows 10 build 18362 on the Slow Ring as a RTM candidate
  • Focus Mode by Google: what it is and how to turn it on
  • TEDx University of Crete Saturday 6 April 2019
ASUS Live Update delivers malware for months was last modified: 25 March, 2019, 8: 48 mm by giorgos

Subscribe to our newsletter

no spam

spread the news

  • Facebook
  • Twitter
  • Reddit
  • Printing
  • Email

Read them Technology News from all over the world, with the validity of iGuRu.gr

Follow us on Google News


Competition: NewsDay: 2018, build, malware, online, Operation ShadowHammer

You May Also Like

British Ministry of Education distributed notebooks with malware
ATMMalScan: Find malware on ATMs
Freki - Malware Analysis Platform

About Us giorgos

George still wonders what he's doing here ...

Previous Post: « Google Unlocked see hidden search results
Next Post: File Explorer New File Explorer in Windows 10 »

Reader Interactions

Comment Policy:

IGuRu.gr does not publish the comments immediately. Malicious comments, comments that include ads, or comments that are offensive are deleted without notice. We do not adopt the opinions expressed by our readers.
Your comments will be displayed after approval by the administrators


Leave your comment
Ακύρωση απάντησης

Your email address is not published. Τα υποχρεωτικά πεδία σημειώνονται με *

 

 © 2021 · iGuRu.gr · ☢ · Keep It Simple Stupid Genesis theme

about  ·   get in touch  ·  rss  ·  sitemap  ·  cough

loadingCancel
Could not post post - check your email address!
Email verification failed, please try again
Your blog can not post posts via email.