sb-au logo
Story image

ASUS' own servers compromised in malware attack

27 Mar 2019

ASUS’ own servers have been compromised in attack that has put hundreds of thousands of users at risk of malware infection.

Asus Live Update is a tool that comes with Asus notebook computer. It helps Asus systems keep up with proprietary firmware and driver updates.

However, the company admitted yesterday that a sophisticated attack on its Live Update servers led to ‘a small number of devices’ being implanted with malicious code, because the attackers used a fake update to push the malware.

Asus believes that the attacks are the work of an Advanced Persistent Threat (APT) group that was trying to target a ‘small and specific’ user group - although Asus has not yet provided details of how the attackers accessed its servers.

According to security firm Avira, early estimates suggest that the compromised update was sent to more than a million devices. Of those, several hundred thousand devices may have installed it.

'So far at Avira, we've seen more than 438,000 executions of the initial installer by Asus customers,'' comments Avira Protection Lab head  Alexander Vukcevic. 

Of those infected devices, around 600 were chosen for an additional stage of malware infection, according to Avira.

''The second stage PE file, which contains the malicious code and will be executed by the installer, is already flagged by Avira as ''TR/ShadowHammer.ME'' with the current pattern update.''

Asus has also fixed the latest version of Live Update (ver. 3.6.8) and added multiple security verification mechanisms to prevent any further malicious manipulation of software updates. It has also implemented an enhanced end-to-end encryption mechanism and strengthened its server-to-end-user software architecture.

Tenable research engineer Satnam Narang, Sr notes that the attacks put the spotlight back on supply chain security.

“Supply chain attacks pose serious risks as they threaten the implicit trust users have in manufacturers and software developers. This can result in end-user scepticism about applying software updates, which often contain critical security updates that, if left unpatched, could be exploited by attackers. However, a common thread among many of these supply chain attacks is that, despite having access to a trove of compromised systems at their disposal, attackers have only targeted a smaller subset of those systems. While the risk of supply chain attacks is concerning, the greater concern lies in failing to patch known vulnerabilities that could be exploited more broadly."

Asus says it is contacting affected users and providing support to help remove the risks. Asus has also created an online security diagnostic tool to check for infected systems.

How do I know whether or not my device has been targeted by the malware attack?

Only a very small number of specific user group were found to have been targeted by this attack and as such it is extremely unlikely that your device has been targeted. However, if you are still concerned about this matter, feel free to use ASUS’ security diagnostic tool or contact ASUS Customer Service for assistance.

What should I do if my device is affected?

Immediately run a backup of your files and restore your operating system to factory settings. This will completely remove the malware from your computer. In order to ensure the security of your information, ASUS recommends that you regularly update your passwords.

How do I make sure that I have the latest version of ASUS Live Update?

You can find out whether or not you have the latest version of ASUS Live Update by following the instructions shown in the link.

Have other ASUS devices been affected by the malware attack?

No, only the version of Live Update used for notebooks has been affected. All other devices remain unaffected.

Story image
5G network security a US$9 billion dollar opportunity - report
The cloud-native nature of 5G networks will have a disruptive and positive impact on the cybersecurity industry in the next few years, with 5G network security presenting a US$9 billion enterprise market opportunity by 2025.More
Story image
SAS digs deeper into the core tenets of responsible AI
What is responsible artificial intelligence (AI)? Is it a technology that does not discriminate against certain groupsMore
Story image
Kroll completes Redscan acquisition, expands cyber risk portfolio
With the addition of Redscan and its extended detection and response (XDR) enabled security operations centre (SOC) platform, Kroll expands its Kroll Responder capabilities to support a wider array of cloud and on-premise telemetry sources.More
Story image
AvePoint brings Salesforce Cloud Backup to channel partners
The product adds to the AvePoint suite of trusted Cloud Backup for Microsoft 365 and Dynamics 365 to provide managed service providers with backup and restore capabilities across multiple, popular SaaS providers.More
Story image
Hybrid IAM solutions are the way of the future, study states
“As this first-of-its-kind research shows, while IT leaders are faced with unique criteria and conditions that shape their IT strategy, hybrid IAM has emerged as a necessity."More
Story image
Gigamon & FireEye tackle security in hybrid cloud environments
The partnership is an extension to a ‘long-standing’ relationship that aims to ‘simplify, secure, and optimise hybrid cloud environments’.More