Rapid Response: ASUS Live Update Attack (Operation ShadowHammer)
ID: 6df04730-6478-512d-aeae-5373c3f304a7
STIX ID: report--6df04730-6478-512d-aeae-5373c3f304a7
Feed Name: Huntress Blog
Threat Score
ASUS's Live Update infrastructure was compromised (June–Nov 2018) to push a backdoored Setup.exe that contained obfuscated shellcode which checked MAC addresses and selectively installed a second-stage malicious payload on about 600 targeted hosts. Non-targeted machines produced an idx.ini artifact; ASUS and third parties released updates and diagnostic tools (Live Update 3.6.8 and MAC-list checkers) to detect and remediate the compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
