ShadowHammer is a Windows supply-chain backdoor operation in which attackers compromised ASUS Live Update infrastructure and distributed a trojanized, legitimately signed software update to a very large victim population during 2018. The malicious update was delivered through ASUS’s trusted update mechanism and signed with valid ASUS certificates, allowing it to blend in with normal software distribution and evade suspicion. The campaign is notable for combining broad distribution with highly selective targeting: the implanted malware remained largely dormant on most infected systems and activated its follow-on behavior only when the host’s network adapter MAC address matched values embedded by the attackers. On selected systems, the malware attempted to retrieve an additional payload, indicating that the initial implant functioned primarily as a targeted access mechanism rather than a mass-payload operator.
The operation is widely characterized as a software supply-chain attack against Windows endpoints, especially ASUS laptops and other devices that shipped with or used the Live Update utility. Public reporting estimated that hundreds of thousands of systems received the malicious update, while only a much smaller subset was intended for second-stage compromise. This selective logic made the campaign unusually stealthy because many victims received the signed backdoor without obvious malicious effects.
Technical and operational reporting has linked ShadowHammer to broader activity associated with the Winnti ecosystem and, in some assessments and legal actions, to APT41. Researchers have also noted technical and tradecraft overlaps with other major supply-chain compromises including CCleaner and ShadowPad. Additional analysis connected ShadowHammer-related tooling to Windows malware development patterns seen in poisoned Microsoft Visual C/C++ runtime initialization paths, reinforcing the view that the campaign belonged to a mature and well-resourced intrusion set with experience in software supply-chain compromise, stealthy persistence, and selective victimization.
ShadowHammer should be understood primarily as a signed Windows backdoor delivered via a trusted vendor update channel for espionage-oriented access to chosen targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ShadowHammer: Malware embedded in Asus Live Update in 2018. ShadowHammer triggers its malicious behavior only if the computer it is running on has a network adapter with the MAC address whitelisted by the attacker.
The company plans to release a full technical paper and presentation about the ASUS attack, which it has dubbed ShadowHammer, next month at its Security Analyst Summit in Singapore.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family referenced in connection with APT41 supply chain attacks.
Supply-chain malware delivered through the ASUS Live Update Utility using compromised digital signatures and hijacked updates; it selectively conducted follow-on activity against specific targets.
...instrumental in our investigations into the LightSpy, TajMahal, Dtrack, ShadowHammer and ShadowPad campaigns.
Supply-chain backdoor delivered through a compromised vendor update server, selectively targeting systems by MAC address.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.