logo

Asus ShadowHammer suggests Supply Chain Hacks are the New Normal

ID: 8ba48750-a391-5652-b908-86c1c47a2545

STIX ID: report--8ba48750-a391-5652-b908-86c1c47a2545

Feed Name: Security Ledger

Threat Score
85/100

Date Published: 2019-03-27

Date Updated: 2026-04-26

Author: Elizabeth Montalbano

...
...

Kaspersky identified 'ShadowHammer', a trojanized ASUS Live Update Utility distributed through ASUS's official update servers and legitimately signed, potentially reaching ~1 million users while specifically targeting ~600 MAC addresses; the report examines supply-chain risks, similar past incidents (NotPetya, Flame, ShadowPad), detection challenges, and recommends tighter code/repository monitoring and threat modeling to defend update mechanisms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.