Hackers used ASUS update software to add back doors to PCs worldwide (Updated)

Updated March 26, 2019: ASUS has now released an updated version of the Live Update tool that patches the ShadowHammer vulnerability. The company also says it has "introduced multiple security verification mechanisms to prevent any malicious manipulation in the form of software updates or other means." The company has also released a tool that can diagnose whether your PC is affected.

ASUS's Live Update utility was compromised by hackers to install malware on PCs, according to a new report from security firm Kaspersky Labs (via Motherboard). The attack, which has been given the name "ShadowHammer," created a back door in the update software, allowing hackers to install malware on machines that had downloaded the compromised utility.

According to Kaspersky Labs, the attack targeted around 600 systems, with the devices' MAC addresses being hardcoded into the malware. That said, Kaspersky has identified 57,000 of its own customers have installed the compromised ASUS Live Update utility, and the full breadth of people that have downloaded it could be upwards of one million, according to the firm's estimates.

"The trojanized utility was signed with a legitimate certificate and was hosted on the official ASUS server dedicated to updates, and that allowed it to stay undetected for a long time," Kaspersky Labs said in a blog post. "The criminals even made sure the file size of the malicious utility stayed the same as that of the original one."

If installed on one of the pesently identified 600 target machines, the back door is then used to install malware on the affected device. If a machine is not among the targets, it simply does nothing, but the back door remains, potentially allowing attackers to compromise PCs further.

Kaspersky Labs says that it has found the same techniques were used "against software from three other vendors." The firm says that it has notified ASUS and the other unnamed companies about the attack, but investigations are still ongoing.

Symantec also confirmed the attack to Motherboard, noting that it identified 13,000 of its own customers who had been affected.

ASUS Live Update is used by the company to ensure users receive BIOS and driver updates, among other things. Though ASUS was alerted of the compromised software in January, a Kaspersky employee who met with ASUS in February told Motherboard that the company has been "largely unresponsive since then and has not notified ASUS customers about the issue."

CATEGORIES
Dan Thorp-Lancaster

Dan Thorp-Lancaster is the former Editor-in-Chief of Windows Central. He began working with Windows Central, Android Central, and iMore as a news writer in 2014 and is obsessed with tech of all sorts. You can follow Dan on Twitter @DthorpL and Instagram @heyitsdtl

Latest in Asus
Image of the ASUS ROG Flow Z13 (2025).
I tested ASUS' Surface Pro on steroids and it's clearly designed for nerds like me, but probably not for you
Image of the ASUS Zenbook A14 (2025).
ASUS Zenbook A14 review: I can't help but love the lightest, longest-lasting AI PC, even with some confusion
Image of the ASUS ROG Flow Z13 (2025).
I get to play with the world's most powerful gaming tablet, and it's totally awesome
The ASUS ROG Flow Z13 (2025) in four positions, including upright with its keyboard attached, upright with its keyboard detached, laying down with its screen up, and laying down with its back up.
You can now preorder ASUS' ridiculously powerful 2-in-1 detachable gaming laptop
The ASUS ROG Flow Z13 (2025) on a desk.
The Surface Pro tablet for gamers is coming back with AMD's most powerful AI processor, and it looks cool as hell
The original ASUS ROG Ally in white, held up by a hand and showing the Armoury Crate launcher on the right and the Armoury Crate Command Center on the left. The "Windows Central Cyber Monday Deals" badge is in the corner.
Cyber Monday is ending with my top recommended gaming handheld at its lowest price ever... Twice?
Latest in News
Cloud servers
Microsoft has killed "several" data center projects in the U.S. and Europe, according to reports
Photo of Microsoft's new sign-in page for Xbox.com using the Microsoft Edge browser.
Over one billion users will get a new Microsoft user experience, and it has a dark mode
Promotional screenshot of heroes fighting a giant in Pillars of Eternity
Obsidian's classic Baldur's Gate successor 'Pillars of Eternity' is getting a surprise turn-based mode later this year, alongside other updates
Atomfall
Atomfall reviews and Metacritic scores are in: Here's a roundup of what everyone's saying about this new Game Pass survival game
Screenshot of one of the new flat world presets in Minecraft.
Minecraft testing new flat world presets and a better way to locate your friends in-game
Cover art for Heroes of the Storm.
Xbox Game Pass will give you more benefits in free-to-play games like Heroes of the Storm