The ASUS Live Update Supply Chain Attack
Updated 5 Oct 2026 · Incident date 1 Jun 2018 · vendor binary
ASUS Live Update Utility -> trojanized June-November 2018 builds (fixed in 3.6.8)setup.exeASUS Live Update versions below 3.6.8 are affected by Operation ShadowHammer. Attackers pushed a trojanized, signed copy of the updater to ASUS machines between June and November 2018.
Many machines received the file. Only machines with a MAC address on a hardcoded list got the second-stage malware.
What happened
Attackers placed a backdoor in the ASUS Live Update utility and sent it through the real ASUS update servers. Kaspersky found the attack in January 2019 and published it on 23 April 2019. Securelist has the full analysis.
The attackers did not build a new tool. They took an old ASUS binary and added their code. The samples carry a timestamp from March 2015. They are signed with two real ASUS certificates from the DigiCert SHA2 Assured ID Code Signing CA, and the samples have no signing timestamp.
The modified Setup.exe contains an obfuscated shellcode payload, per Huntress. The code hashes the MAC addresses of the local network adapters. It compares the hashes with a built-in table. If one matches, it downloads a second payload. If none match, it does nothing. Kaspersky extracted more than 600 unique MAC addresses from over 200 samples. It saw the injected code on more than 57,000 of its own users' machines. Huntress puts the number of machines that received the backdoored update at about one million.
This case shows why a valid signature is not enough. The file was signed and came from the vendor. The new capability was in setup.exe. Vigilance compares the build you trust with the new one and reports a file that gains a new power.
Affected versions
ASUS Live Update versions below 3.6.8 are affected, per the CERT-EU advisory.
- Huntress lists the trojanized builds as 3.5.9, 3.6.0, 3.6.2 and 3.6.5.
- The builds went out through ASUS update servers from June to November 2018.
- ASUS released the fixed Live Update 3.6.8 on 26 March 2019.
Huntress notes that four malicious ZIP files were hosted on the ASUS servers.
Indicators of compromise
These indicators come from Securelist and Huntress.
- A file named
idx.ini. The shellcode writes it up to two directory levels above the place whereSetup.exeran. - The domain
asushotfix[.]com, with the paths/logo.jpgand/logo2.jpg. - Second-stage servers listed by Securelist:
103.19.3[.]17,103.19.3[.]43,103.19.3[.]44,117.16.142[.]9,23.236.77[.]175and23.236.77[.]177. - A Setup.exe sample with MD5
0f49621b06f2cdaac8850c6e9581a594,63f2fe96de336b6097806b22b5ab941aor17a36ac3e31f3a18936552aff2c80249. These are a small part of the full Securelist list. - Code signed as ASUSTeK Computer Inc. with certificate serial
0ff067d801f7daeeae842e9fe5f610eaor05e6a0be5ac359c7ff11f4b467ab20fc.
How to check
Find the Live Update version, then search the disk for the idx.ini marker file. On Windows, run this in a Command Prompt.
where /r C:\ idx.ini
Open the Live Update app to read its version number. The version must be 3.6.8 or higher. To see if your machine was a target, use the diagnostic tools from ASUS or Kaspersky. They compare the MAC addresses of your adapters with the target list. A machine on the list can need a full review.
What to do now
- Update ASUS Live Update to 3.6.8 or later.
- Search for
idx.iniand for traffic toasushotfix.comin your logs. - Run the ASUS or Kaspersky diagnostic tool on each ASUS machine.
- If a machine is on the target list or has
idx.ini, treat it as compromised. Rebuild it and rotate the credentials that it held. - On a fleet, keep a record of the hashes of vendor updater files and review any change before the update runs.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 25 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED setup.exe It now downloads from the internet and runs other programs. It did not before.
Frequently asked questions
Which ASUS Live Update versions were affected by ShadowHammer?
Versions below 3.6.8. Huntress lists the trojanized builds as 3.5.9, 3.6.0, 3.6.2 and 3.6.5. ASUS released 3.6.8 on 26 March 2019.
How do I check if my ASUS laptop got the ShadowHammer backdoor?
Search the disk for a file named idx.ini and check that Live Update is version 3.6.8 or later. Use the ASUS or Kaspersky diagnostic tool to see if your MAC address was on the target list.
Who did the ShadowHammer backdoor target?
The code carried a list of more than 600 MAC addresses. Only machines with a matching adapter got the second-stage payload.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.