Toutes les vulnérabilités
HIGHSupply chainexploited in the wild

SC-ASUS-SHADOWHAMMER-2019

Software vendor · ASUS Live Update

Résumé

Disclosed by Kaspersky in January 2019, Operation ShadowHammer compromised the ASUS Live Update utility pre-installed on most ASUS computers, running between June and November 2018. An APT group modified the legitimate updater on ASUS's official servers and signed the backdoored binary with a stolen legitimate ASUS certificate, matching the original file size to avoid detection. Over a million users received the backdoored update, but it was a surgical attack: it checked the host MAC address against a hard-coded list of around 600 targets before fetching a second-stage payload.

Références

Vulnérabilités liées

Tout Supply chain →