Skip to main content
  1. Home
  2. Computing
  3. News

Own an Asus computer? Malware might be hiding in your system

Add as a preferred source on Google
Asus ZenBook 14 UX433FN
Mark Coppock/Digtial Trends

If you own an Asus computer, your system might have been infected by malware distributed from the tool you typically use to update BIOS and install other important security patches. That’s all according to a new report from researchers at the Russian-based cybersecurity company, Kaspersky Lab.

The initial hack was first discovered in January and, in the period of five months, could have impacted up to one million different computers. According to Kaspersky, hackers apparently leveraged a back door attack and modified the ASUS Live Update Utility so it delivered a payload with malware — making it seem as though it was coming from official sources.

Recommended Videos

The backdoor was given the name “ShadowHammer” and peaked between June and November 2018. Up to 57,000 people using Kaspersky software were impacted, though it is believed that only 600 specific computers were originally intended as targets. Hackers even went as far as to ensure that the files were signed with authentic digital certificates — and to make sure that file sizes were the same size as ones distributed by Asus.

In response, Asus has released an online security diagnostic tool which helps check for affected systems. The company encourages users who are concerned to run it as a precaution. A fix in the latest version (3.6.8) of the Live Update Software addresses the issue and introduces multiple security verification mechanisms and end-to-end encryption to prevent malicious manipulation in the form of security updates.

Asus has also updated and strengthened its server-t0-end user software architecture to prevent similar attacks from happening in the future.

“Asus Live Update is a proprietary tool supplied with ASUS notebook computers to ensure that the system always benefits from the latest drivers and firmware from ASUS. A small number of devices have been implanted with malicious code through a sophisticated attack on our Live Update servers in an attempt to target a very small and specific user group,” said Asus in a statement.

Other than Kaspersky Lab, Symantec, a cybersecurity firm based in the United States, also confirmed the discovery of the ShadowHammer malware. According to a report from Motherboard, up to 13,000 computers running Symantec software were impacted.

This type of supply-chain attack is not necessarily new. Back in 2017, the popular CCleaner system maintenance application was found to have distributed malware to millions of computers through its official channels. That was eventually patched, but not before the attacks went on for a period of 22 days. These attacks are also designed to reduce trust in legitimate sources and institutions.

Updated on March 27 with a statement from Asus, and additional information on online security diagnostic tool

Arif Bacchus
Arif Bacchus is a native New Yorker and a fan of all things technology. Arif works as a freelance writer at Digital Trends…
Alexa+ just quietly became way more useful, if your gadgets are on this list
Your smart home is about to get a whole lot smarter.
Adult, Male, Man

You might have asked Alexa to do plenty of dumb things over the years, but "figure out which of my washer's 30 cycles actually means cold wash" might not have been one of them.

Turns out, Amazon just built the toolkit that makes exactly that possible, and it's rolling out across a genuinely huge list of brands today.

Read more
How to set up selfie video sign-in for your Google account
Your face can now serve as a way to get back into your Google account. Here's how to set it up.
Google account selfie sign in tutorial featured

Losing access to a Google account is rarely a quick fix, but Google has been actively working to make things easier. Last year, the company introduced a feature called Recovery Contacts that lets you designate a trusted friend or family member to verify your identity if you ever get locked out. Now, Google has introduced a new option, one that uses your face to get you back in instead of a phone call to a friend.

Like Recovery Contacts, the new selfie video authentication feature requires some setup before you can use your face to sign into your Google account. This involves recording the reference video that Google will use to verify your identity whenever you attempt to log in this way. Here's how to set up selfie video sign-in for your Google account.

Read more
Framework Desktop packs Ryzen AI Max, up to 192GB of RAM, and local AI into a mini PC
192GB of RAM in a desktop this small? Framework says yes.
Framework Desktop feature

Framework has built a reputation for shipping things other PC makers won't even attempt, and its latest teaser keeps that streak alive. At AMD's Advancing AI event, the company previewed a new version of its Framework Desktop, and this one is clearly built with one goal in mind: running large AI models locally on your computer. If you have been eyeing a way to run local AI, this could be the machine to watch.

So what's actually new here?

Read more