Attackers compromised ASUS's Live Update infrastructure and used legitimate ASUS digital certificates to distribute a trojanized software update to Windows users in a supply-chain attack dubbed ShadowHammer. The malicious update was reportedly delivered between June and November 2018 and reached a large number of systems, with Kaspersky identifying more than 57,000 affected customers and Symantec seeing at least 13,000 among its own users; reporting indicated the broader victim count may have reached into the hundreds of thousands.
Researchers said the operation was highly selective despite its broad distribution: the backdoored updater checked hashed MAC addresses against an embedded target list and only contacted a command-and-control domain to retrieve a second-stage payload on roughly 600 intended machines. SentinelOne and other researchers described the campaign as a tailored, stealthy supply-chain intrusion linked to activity associated with ShadowPad and the CCleaner compromise, while criticism mounted over ASUS's response, including allegations that the company was slow to acknowledge the breach and revoke compromised certificates.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
SentinelOne released additional public analysis of the ASUS ShadowHammer operation, describing it as a tailored supply-chain attack. The publication expanded technical understanding of the campaign after the initial disclosures.
At the time of public reporting, Kaspersky said ASUS had denied the compromise, responded slowly, and had not promptly revoked the compromised certificates. This added detail clarified the vendor-response aspect of the incident.
Security researchers at Kaspersky disclosed the ASUS supply-chain attack and named it ShadowHammer, while Symantec independently confirmed the activity. Kaspersky said more than 57,000 of its customers were affected, and Symantec said at least 13,000 of its customers received the malicious update.
Between June and November 2018, ASUS Live Update delivered backdoored updates to a large number of Windows systems. The malware selectively checked hashed MAC addresses to identify roughly 600 intended targets before attempting to retrieve a second-stage payload.
Attackers breached ASUS's software update infrastructure and abused legitimate ASUS digital certificates to prepare trojanized Live Update packages for distribution. Researchers later linked the operation to the ShadowHammer supply-chain campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.