Asus pushes patch after hackers used updates to send malware
Thousands of Asus computers were infected with malware from the company’s own update tool, researchers from Kaspersky Lab said Monday.
The researchers discovered the attack in January, after hackers took over the Asus Live Update Utility to quietly install malware on devices. The hack was first reported by Motherboard.
On Tuesday, Asus said it’s fixed the vulnerability in the another version of its Live Update tool, meaning you’ll have to satisfactory the software to resolve the issue.
“Asus customer service has been inward out to affected users and providing assistance to convicted that the security risks are removed,” the company said in a statement.
The hack, which Kaspersky Lab is calling Operation ShadowHammer, went on between June and November 2018. Kaspersky Lab spurious that it affected more than 57,000 people using its products. The Russia-based cybersecurity company was only able to find those numbers for its own users, and estimates that the malware could affect more than a million Asus owners worldwide.
Symantec, another cybersecurity company, found the same malware from Asus updates, and cited at least 13,000 computers affected by the contest. The company said that 80 percent of victims were consumers, while 20 percent were organizations.
The update tool is preinstalled on the greatest of new Asus devices.
The attackers were able to infect devices deprived of raising red flags because they used Asus’ legitimate confidence certificate, which was hosted on the computer manufacturer’s servers.
Asus is a Taiwan-based computer commercial, and one of the top consumer notebook vendors in the domain, with millions of laptops worldwide.
“The selected vendors are very attractive targets for APT [advanced persistent threat] groups that worthy want to take advantage of their vast customer base,” Vitaly Kamluk, director of Kaspersky Lab’s Global Research and Analysis Team, said in a statement.
Malware can arrive on your devices in a lot of ways — downloading a file from an email, opening a PDF you shouldn’t have or via browser-based attacks.
The hack on Asus’ automatic update tool points to novel kind of concern, in which people have to be unnerved about patches from the source itself as hackers seek to expenditure a trusted relationship. Supply chain attacks are not new: In 2017, the popular software tool CCleaner was hijacked to install malware on millions of computers.
Distrust in automatic updates leads to novel kind of threat, as many companies often rely on republic to patch their devices to defend against new malware. The majority of computers infected with the WannaCry ransomware, for instance, were hit because they didn’t install a confidence update issued in 2017.
While it’s capable of attacking millions, the malware had a specific set of targets, researchers fraudulent. Once it was installed, the backdoor checked the device’s MAC address. If it matched one of the hacker’s targets, it then installed novel set of malware, researchers said.
Kaspersky Lab researchers said they identified more than 600 MAC addresses, and released a tool for people to check whether they were beleaguered by the attack. The cybersecurity company said it’s notified Asus, and the investigation is ongoing.
Originally published March 25 at 7:16 a.m. PT.
Updated March 26 at 6:26 a.m. PT: Includes response from Asus.
Source
Blog Archive
-
▼
2022
(101)
-
▼
January
(30)
- Garmin Instinct 2 promises you’ll never charge you...
- 6 Tips to Help Secure Your Android Device Data
- T-Mobile, SpaceX Partner to Use Starlink Satellite...
- The Beatles land on TikTok, and you can now offici...
- Spider-Man: No Way Home’s Willem Dafoe was determi...
- How a $50 gadget is saving $840 a year on my elect...
- Still using Windows 7? These security tips will pr...
- Acer Iconia W700 review: Laptop power in a tablet ...
- Parrot Anafi review: Parrot Anafi folding 4K HDR d...
- Asus pushes patch after hackers used updates to se...
- Samsung’s Galaxy Z Flip 3 is nearly $400 less than...
- I Almost Ditched My Apple Watch for This Stylish, ...
- Google Pixel 6A vs. Pixel 6: What Makes the Cheape...
- NHTSA to EV Drivers: No Selectable Low-Speed Sound...
- This Large-Screen HP Laptop is $250 Off Today Only...
- Free Starbucks holiday reusable cups today: How to...
- AMD Radeon RX 6800 series graphics cards have seri...
- Ukraine Invasion: What to Know Today About Inflati...
- Huawei Mate 20 Pro review: An elite smartphone wit...
- Facebook Rolls Out New Home and Feeds Tabs - Virtualo
- Watch Bugatti Dyno-Test the 1,598-HP Chiron Super ...
- Amazon’s ‘Android Days’ Promo Brings All-Time-Low ...
- MSI Raider GE76 gaming laptop has the fastest of e...
- 2021 Honda Accord sticks to the sedan formula - Vi...
- Current Mortgage Rates: Compare Today’s Rates - Vi...
- 2022 Kia Sorento plug-in hybrid rolls in with $46,...
- This poop-themed anime game wants you to care abou...
- I Could Get Hooked on This Salad Delivery Service ...
- State Stimulus Payments 2022: Is Your State Mailin...
- Federal Reserve will begin tapering: What does tha...
-
▼
January
(30)
Labels
Total Pageviews
Search This Blog
Popular Posts
-
What is indictment for a felony, what is indictment mean, what is indictment in criminal law, what is indictment non mapped, what is indictm...
-
The definition of indictment, kind words that start with a, what kind of word starts a dependent clause, thank you for your kind words, kind...
-
Mlb season 2023 opening day, opening day for mlb 2023, mlb opening day 2023 date, mlb opening day 2023 tickets, mlb opening day 2023 games, ...