Operation ShadowHammer is the name given to an advanced persistent threat campaign centered on a supply-chain compromise of ASUS Live Update in 2018. The operators breached ASUS infrastructure and distributed trojanized software updates signed and delivered through the legitimate update channel between June and November 2018. The campaign was highly selective: the malicious update logic checked device identifiers against a hard-coded target list and only proceeded for a small intended victim set, indicating a surgical targeting model rather than broad opportunistic compromise. The operation is notable for combining trusted software distribution abuse with precise victim selection, a hallmark of sophisticated espionage-oriented activity. High-confidence public reporting in the supplied facts supports the supply-chain intrusion, selective targeting, and post-compromise delivery of unauthorized code, but does not reliably attribute the campaign to a specific named nation-state cluster or country of origin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.