logo

Rapid Response: ASUS Live Update Attack (Operation ShadowHammer)

ID: 6df04730-6478-512d-aeae-5373c3f304a7

STIX ID: report--6df04730-6478-512d-aeae-5373c3f304a7

Feed Name: Huntress Blog

Threat Score
85/100

Date Published: 2019-03-26

Date Updated: 2026-04-28

...
...

ASUS's Live Update infrastructure was compromised (June–Nov 2018) to push a backdoored Setup.exe that contained obfuscated shellcode which checked MAC addresses and selectively installed a second-stage malicious payload on about 600 targeted hosts. Non-targeted machines produced an idx.ini artifact; ASUS and third parties released updates and diagnostic tools (Live Update 3.6.8 and MAC-list checkers) to detect and remediate the compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.