cl-au logo
Story image

ASUS' own servers compromised in malware attack

27 Mar 2019

ASUS’ own servers have been compromised in attack that has put hundreds of thousands of users at risk of malware infection.

Asus Live Update is a tool that comes with Asus notebook computer. It helps Asus systems keep up with proprietary firmware and driver updates.

However, the company admitted yesterday that a sophisticated attack on its Live Update servers led to ‘a small number of devices’ being implanted with malicious code, because the attackers used a fake update to push the malware.

Asus believes that the attacks are the work of an Advanced Persistent Threat (APT) group that was trying to target a ‘small and specific’ user group - although Asus has not yet provided details of how the attackers accessed its servers.

According to security firm Avira, early estimates suggest that the compromised update was sent to more than a million devices. Of those, several hundred thousand devices may have installed it.

'So far at Avira, we've seen more than 438,000 executions of the initial installer by Asus customers,'' comments Avira Protection Lab head  Alexander Vukcevic. 

Of those infected devices, around 600 were chosen for an additional stage of malware infection, according to Avira.

''The second stage PE file, which contains the malicious code and will be executed by the installer, is already flagged by Avira as ''TR/ShadowHammer.ME'' with the current pattern update.''

Asus has also fixed the latest version of Live Update (ver. 3.6.8) and added multiple security verification mechanisms to prevent any further malicious manipulation of software updates. It has also implemented an enhanced end-to-end encryption mechanism and strengthened its server-to-end-user software architecture.

Tenable research engineer Satnam Narang, Sr notes that the attacks put the spotlight back on supply chain security.

“Supply chain attacks pose serious risks as they threaten the implicit trust users have in manufacturers and software developers. This can result in end-user scepticism about applying software updates, which often contain critical security updates that, if left unpatched, could be exploited by attackers. However, a common thread among many of these supply chain attacks is that, despite having access to a trove of compromised systems at their disposal, attackers have only targeted a smaller subset of those systems. While the risk of supply chain attacks is concerning, the greater concern lies in failing to patch known vulnerabilities that could be exploited more broadly."

Asus says it is contacting affected users and providing support to help remove the risks. Asus has also created an online security diagnostic tool to check for infected systems.

How do I know whether or not my device has been targeted by the malware attack?

Only a very small number of specific user group were found to have been targeted by this attack and as such it is extremely unlikely that your device has been targeted. However, if you are still concerned about this matter, feel free to use ASUS’ security diagnostic tool or contact ASUS Customer Service for assistance.

What should I do if my device is affected?

Immediately run a backup of your files and restore your operating system to factory settings. This will completely remove the malware from your computer. In order to ensure the security of your information, ASUS recommends that you regularly update your passwords.

How do I make sure that I have the latest version of ASUS Live Update?

You can find out whether or not you have the latest version of ASUS Live Update by following the instructions shown in the link.

Have other ASUS devices been affected by the malware attack?

No, only the version of Live Update used for notebooks has been affected. All other devices remain unaffected.

Story image
Airlock Digital seeks to empower Aussie SMEs with AustCyber funding
“With more SMEs and other organisations looking to adopt application whitelisting as a primary cyber defence mechanism, we plan to significantly expand Airlock Digital's partner network."More
Story image
Citrix partners with HPE to aid employees returning to offices
“Citrix is one of the partners that HPE is working very closely with to enhance existing solutions with components that are tailor made for COVID-19 response.”More
Story image
CenturyLink expands cloud alliance with Dell and VMware in Asia Pacific
The partnership is designed to offer a hybrid cloud solution to help digital businesses in Asia Pacific successfully modernise their application workloads and manage their cloud journey.More
Story image
PNY launches high-performance XLR8 Gaming RGB Memory
PNY’s XLR8 range is aimed at the PC enthusiast market. The range sports a more aggressive industrial styling suited to high-end PC cases that show off the components inside.More
Story image
Arrow and RiskIQ sign A/NZ distribution agreement
“Our teaming with RiskIQ offers the A/NZ channel access to their innovative approach to solving contemporary security challenges, which are being experienced across a range of industries and organisations.”More
Story image
Hands-on review: JBL Tune 220TWS
Another great part of the design is the earbuds themselves. Most other earbuds on the market can’t be worn for more than two hours at a time because of the amount of pressure they put on ear canals. Thankfully, the JBL Tune 220 were designed with all-day wear in mind. More