Toutes les vulnérabilités
HIGHSupply chainexploited in the wildcurated

SC-ASUS-SHADOWHAMMER-2019

Software vendor · ASUS Live Update

Résumé

Operation ShadowHammer, revealed by Kaspersky in early 2019, backdoored one of the most trusted programs on millions of computers: the ASUS Live Update utility that ships pre-installed on ASUS PCs to deliver driver and firmware updates. An APT group compromised ASUS's own update servers and pushed a malicious version, signed with a legitimate ASUS certificate so it looked completely authentic, to over a million users. But the attackers did not want a million victims. The malware checked each machine's network address against a hard-coded list of about 600 specific targets and only activated for them, ignoring everyone else. It is the textbook surgical supply-chain attack: poison the many to reach a precise few.

How it happened

ASUS Live Update comes pre-installed on most ASUS computers and fetches updates automatically with a high level of trust. An APT group compromised ASUS's official update infrastructure in mid-to-late 2018 and replaced the legitimate updater with a backdoored version. To make it indistinguishable from a real update, they backdoored an old, legitimately-signed 2015-era build (overwriting a small code block in place to keep the file size identical) and signed it with stolen ASUS code-signing certificates, switching to a second valid ASUS certificate when the first expired mid-campaign, a sign of sustained access to ASUS's signing capability.

So the malicious update arrived from ASUS's real servers, signed by ASUS, and over a million users installed it. But it was built as a sniper, not a shotgun. On each machine the malware read the network adapter's MAC address, computed its MD5 hash, and compared it against hard-coded tables of around 600 target hashes. Only for those few did it reach out for a second-stage payload; for everyone else, the backdoor simply sat inert. It is a supply-chain attack used as a precision-guided weapon.

The damage

More than a million users received the backdoored updater, while roughly 600 carefully chosen machines were the real targets. Kaspersky discovered the operation at the end of January 2019, briefly disclosed it in March, and published the full technical analysis in April; ASUS issued a fix and a tool that let users check whether their machine was on the target list. ASUS publicly downplayed the scale, calling it "a very small and specific user group," which contradicted Kaspersky's roughly one-million distribution figure, a now-classic example of vendor minimisation during a supply-chain disclosure. The intended victims behind the ~600 addresses were never fully identified publicly. The tradecraft, stolen certificates, file-size matching, and razor-narrow targeting, pointed to a sophisticated state-linked group (Kaspersky's BARIUM, overlapping with the Winnti / APT41 cluster), the same actor tied to the CCleaner attack, though the link was assessed as probable rather than proven.

Why ASUS ShadowHammer still matters

It is nearly identical in shape to the CCleaner compromise, and attributed to the same actor cluster: take over a trusted vendor's update channel, sign the malware with a valid certificate, distribute it to millions as a funnel, and activate only on a tiny curated list of targets. Kaspersky found the same technique used against software from at least three other vendors in Asia, so ShadowHammer was one node in a wider campaign, not an isolated ASUS event. The deeper lesson, as the researchers put it, is that your compiler and pipeline can lie to you: the malicious binary diverged from the source, so source-code review alone could never have caught it. The defences are the by-now familiar supply-chain hardening: isolate the build and release pipeline, protect signing keys in hardware, require reproducible and verified builds with provenance, monitor the integrity of released artifacts and update servers (not just source), and minimise and tightly control auto-updating pre-installed software.

Comment le corriger

  • Pull the trojanized updater, ship a clean signed rebuild, and give users a way to check whether they were among the targeted machines.
  • Rebuild the release pipeline from trusted media and rotate the compromised code-signing certificates and all CI/CD credentials.
  • Hunt among high-value users for the second-stage payload and persistence.

Comment l’éviter

  • Harden and isolate the build and release pipeline, protect signing keys in hardware, and require reproducible, verified builds with provenance.
  • Monitor the integrity of released artifacts and update servers, not just source code; the malware was served from the real servers, validly signed.
  • Minimize and tightly control auto-updating pre-installed software, which is a high-privilege, high-trust attack surface.
  • Remember a valid signature proves origin, not safety; downstream defenders should still watch update behavior.

Références

Vulnérabilités liées

Tout Supply chain →