
- #ASUS LIVE UPDATE NO UPDATES HOW TO#
- #ASUS LIVE UPDATE NO UPDATES UPDATE#
- #ASUS LIVE UPDATE NO UPDATES VERIFICATION#
Second stage is deployed only if both addresses match. In some cases, the #shadowhammer backdoor checks both the NIC and WiFi adapter MACs to identify the victim for further exploitation.
#ASUS LIVE UPDATE NO UPDATES UPDATE#
Kaspersky said the backdoored Live Update versions they collected featured more than 600 unique MAC addresses on which the ShadowHammer malware would launch further attacks.

The ShadowHammer operation, as Kaspersky is calling it, infected hundreds of thousands of users, but the ShadowHammer malware hidden inside the Live Update tool didn't infect users with additional payloads unless their device had a specific MAC address. The company said that only the Live Update tool used with notebooks had been backdoored, and not all instances of its app -used as a firmware update utility on millions of devices across the world.ĪSUS was unable to put a solid figure on the number of impacted users, despite having direct access to its own server logs and knowing of the hack for roughly two months. However, in its press release today, ASUS downplayed this estimate and said that just "a small number of devices have been implanted with malicious code." Initial assessments by Kaspersky Lab and Symantec estimated the number of infected users ranging between 500,000 and 1,000,000 users.

The company's statement comes after tech news site Motherboard revealed yesterday that a group of nation-state hackers compromised ASUS' Live Update infrastructure and delivered a backdoored version of the ASUS Live Update tool.
#ASUS LIVE UPDATE NO UPDATES VERIFICATION#
The company said ASUS Live Update v3.6.8 "introduced multiple security verification mechanisms to prevent any malicious manipulation in the form of software updates or other means, and implemented an enhanced end-to-end encryption mechanism."ĪSUS also said it updated and strengthened its "server-to-end-user software architecture to prevent similar attacks from happening in the future." ASUS: Only notebook users were targeted
#ASUS LIVE UPDATE NO UPDATES HOW TO#

