ASUS' live update software hacked, signed with ASUS digital certificate

Questions on how we spend our money and our time - consumer goods and services, home and vehicle, leisure and recreational activities
Post Reply
Topic Author
donfairplay
Posts: 249
Joined: Mon Oct 06, 2008 8:16 pm

ASUS' live update software hacked, signed with ASUS digital certificate

Post by donfairplay »

https://motherboard.vice.com/en_us/arti ... -computers

New supply-chain attack/hack. This time ASUS' live update software has a backdoor, and was signed with ASUS' digital certificate. Estimated up to half a million compromised machines.

Named ShadowHammer, due to its similarities with the CCleaner (32 bit) supply-chain attack.

ASUS denied Kaspersky's inquiry two months ago, Symantec confirmed their findings Friday.
1claire
Posts: 9
Joined: Fri Mar 15, 2019 12:00 am

Re: ASUS' live update software hacked, signed with ASUS digital certificate

Post by 1claire »

This is not good news for this brand, security nowadays must be at its finest to avoid hacking.
fourwheelcycle
Posts: 1727
Joined: Sun May 25, 2014 5:55 pm

Re: ASUS' live update software hacked, signed with ASUS digital certificate

Post by fourwheelcycle »

Great. I did lots of research last November and ended up buying a new Asus router! I use it for our Macs, and we do not live in Russia, so maybe we will be OK. I have not seen any info on how to tell if you have the malware in your router or computers, or which specific updates from Asus were used to transmit the malware.
GmanJeff
Posts: 914
Joined: Sun Jun 11, 2017 7:12 am

Re: ASUS' live update software hacked, signed with ASUS digital certificate

Post by GmanJeff »

Kaspersky's site has a tool which purports to look for this vulnerability. Reporting suggests the attack is highly focused on a limited number of large enterprise users. That is, even though many consumer end-user machines may be infected, the infection will remain dormant on them.
User avatar
Doom&Gloom
Posts: 4978
Joined: Thu May 08, 2014 3:36 pm

Re: ASUS' live update software hacked, signed with ASUS digital certificate

Post by Doom&Gloom »

fourwheelcycle wrote: Tue Mar 26, 2019 6:46 am Great. I did lots of research last November and ended up buying a new Asus router! I use it for our Macs, and we do not live in Russia, so maybe we will be OK. I have not seen any info on how to tell if you have the malware in your router or computers, or which specific updates from Asus were used to transmit the malware.
As I understand it, routers are unaffected. Only Asus Windows PCs & laptops.
2015
Posts: 2906
Joined: Mon Feb 10, 2014 1:32 pm

Re: ASUS' live update software hacked, signed with ASUS digital certificate

Post by 2015 »

On this page ASUS provides a link to a diagnostic tool to check if your computer has been compromised:

https://www.asus.com/News/hqfgVUyZ6uyAyJe1

Also, from Reddit:
This only affects ASUS machines running Live Update that was downloaded between June and November of 2018. That puts approximately 3-4 million machines sold by ASUS in that time frame, in addition to downloads from the web. It's likely that this malware is on your machine, but is dormant because only 600 specific MAC addresses would trigger the next stage of the malware. As of now, even if you have the malware it's likely not doing anything. Instead, this exposes a huge security oversight and example of attacking at the vendor/source level.
Post Reply