Over a million Asus laptops could have been hacked

Image credit: TechRadar

Update: Asus has been in contact to confirm that its laptops have been subjected to an attack, and outlined its steps to fix the security issue. Read our full story on Asus' response to the attack for more information.

It appears that Asus is in some hot water after being compromised by hackers, who have hijacked the laptop maker’s update service to push malicious software onto Asus laptops.

This is according to security firm Kaspersky, who wrote a blog post describing how the hackers managed to gain access to the Asus Live Update Utility – which delivers software updates to Asus notebooks and PCs – using it to install a backdoor on machines around the world.

Apparently, this backdoor – given the suitably ominous codename ShadowHammer – was delivered to an estimated one million Windows computers, or thereabouts, a rather staggering amount over a period of five months.

The slightly better news – at least compared to that jaw-flooring distribution statistic – is that the hackers were seemingly only interested in targeting a minority of those machines: 600 of them in fact. These PCs had further malware installed on them via the backdoor.

The malicious file was cleverly disguised in that it was signed with authentic Asus digital certificates, and the perpetrators made sure the file size of the update utility remained exactly the same as the original so as not to raise any suspicions on that front.

The fact that the hackers only actively exploited a small number of machines also helped the malware stay under the radar. Now the cat is out of the bag, though, perhaps there is a danger that a wider campaign of malicious activity could be opened up.

Further trouble down the road?

Kaspersky further notes that its investigation is still ongoing, and that attacks using the same techniques have apparently been aimed against software (presumably update routines) from three other PC manufacturers.

These companies have all been notified, as has Asus – so who knows, we may shortly hear more about further potential compromises when it comes to other notebook makers.

Kaspersky has naturally updated its own security software to detect and block this malware, but advises that owners of Asus machines should still update the Asus Live Update Utility.

We have contacted Asus for a comment on ShadowHammer, and you can read our full report on Asus' response.

As well as Kaspersky, rival security outfit Symantec has also found evidence of infection by this malware, with at least 13,000 PCs with Symantec antivirus software installed being hit by the backdoor.

Via Motherboard

TOPICS

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Cyber Crime
A person scanning a QR code on a smartphone
Quishing is the new QR code scam you need to watch out for – here's how to stay safe
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Text Phishing Scams
Do not fall for this dangerous Amazon shopping scam
Cyber-security
Safeguarding against next-gen cyber risks
The North Face jacket
Thousands of North Face customers accounts hacked, personal data stolen
Smartphone hacked with data flow in the background
9 signs your phone has been hacked
Latest in News
TCL QM7K TV on orange background
TCL’s big, bright new mid-range mini-LED TVs have built-in Bang & Olufsen sound
Homepage of Manus, a new Chinese artificial intelligence agent capable of handling complex, real-world tasks, is seen on the screen of an iPhone.
Manus AI may be the new DeepSeek, but initial users report problems
Google Maps
Nightmare Google Maps glitch is deleting timelines, and there isn't a fix yet
Twitter social media application change logo to X. Elon Musk CEO of twitter rebranded Twitter to 'X'. Social media application technology concept.
X is down again – Elon Musk confirms 'massive cyberattack' as former Twitter site hit by fourth outage today
Joe Goldberg and Kate Lockwood sitting at a table and looking at the camera in You season 5.
Netflix releases a killer new trailer for You season 5 but my favorite character is missing from Joe's final chapter
Person using Dyson V8 vacuum
Dyson vacuums have one big problem and I don't understand why