The Everest ransomware group has publicly claimed responsibility for a significant breach of ASUS, a leading global hardware and electronics manufacturer. According to statements posted on a dark web leak site, Everest alleges it has stolen over 1TB of data from ASUS, including proprietary camera source code, firmware, and potentially other sensitive intellectual property. The group has demanded that ASUS contact them via the encrypted messaging platform Qtox within 21 hours, though no ransom amount has been disclosed. At this time, ASUS has not confirmed or denied the breach, and the exact nature and sensitivity of the compromised data remain unverified.
This incident follows a pattern of recent Everest ransomware claims against other high-profile organizations, such as Under Armour, Petrobras, and Iberia airline, which involved theft of user data and internal documentation. If substantiated, the breach would represent a major compromise for ASUS, which previously suffered the ShadowHammer supply chain attack in 2019. The situation underscores the ongoing threat posed by ransomware groups to major technology manufacturers and the potential for large-scale intellectual property theft and operational disruption.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
In connection with the ASUS-related leak, Everest also claimed to have stolen data from ArcSoft and Qualcomm, including source code, firmware, AI models, and other technical assets. This broadened the incident from a single-company breach claim to a wider supply-chain compromise allegation.
ASUS confirmed that a third-party supplier had been compromised after Everest published sample leaked data as proof of the intrusion. The company said the exposure involved some phone camera source code and stated that its products, internal systems, and user data were not affected.
The Everest ransomware group publicly claimed it had breached ASUS and stolen more than 1 TB of data, including proprietary camera source code and firmware. The group demanded that ASUS respond via Qtox within 21 hours, but no ransom amount was disclosed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.