Researchers reported that Operation ShadowHammer compromised the ASUS Live Update utility, turning a trusted software update channel into a malware delivery mechanism. The campaign was linked to the broader pattern of software supply chain intrusions seen in incidents such as CCleaner, ShadowPad, NotPetya via M.E.Doc, XcodeGhost, Havex, and the event-stream compromise, where attackers abused legitimate development, build, or distribution processes to reach victims at scale.
Analysis of these attacks highlighted a particularly stealthy technique: tampering with Microsoft Visual C/C++ runtime (CRT) behavior during compilation or linking so malicious code is inserted at build time rather than appearing in source code. In the ShadowPad case, researchers said attackers poisoned the DLL nssock2.dll by abusing the function pointer table used by the CRT routine _initterm(), illustrating how trusted binaries can be backdoored in ways that are difficult to detect. The reports said defenders should prioritize integrity checks across build environments, compiler libraries, third-party components, update infrastructure, and release systems to reduce exposure to similar supply chain compromises.

Trace attribution and downstream blast radius.
13 events from the most recent confirmed update back to the earliest known activity.
A gaming industry attack involving Winnti.A was publicized, describing the compromise of three gaming companies' main executables.
The npm package event-stream was compromised after publishing rights were delegated to another person, who added the malicious flatmap-stream package as a direct dependency to target Copay release build environments and steal bitcoins.
Attackers compromised a computer vendor's update server in Operation ShadowHammer and targeted users based on MAC addresses.
A poisoned MediaGet update delivered a trojanized copy of mediaget.exe.
The CCleaner case involved the compromise of Piriform and the insertion of a backdoor into CCleaner.
Attackers compromised NetSarang Computer, Inc. and backdoored all of the company's products by injecting malicious code into the shared library nssock2.dll.
The Nyetya/NotPetya attack on M.E.Doc used the software's update system to deliver destructive ransomware, including a backdoored .NET module named ZvitPublishedObjects.dll.
A trojanized version of Apple's Xcode IDE was hosted on Chinese file-sharing services, causing iOS apps built with it to become infected.
The KingSlayer attack on EventID compromised both the Windows Event Log Analyzer source code and its update server.
Havex-related compromises of industrial control system websites and software installers also occurred in 2014.
In the Monju incident, attackers compromised the update server for GOM Player and distributed a variant of Gh0st RAT to specific targets.
Multiple industrial control system websites and software installers were compromised in Havex incidents affecting the sector.
The Winnti group targeted the online video game industry by compromising multiple companies' update servers and attempting to spread malicious implants or libraries using AheadLib.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 33 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
trendmicro.com
Open sourcesecurelist.com
Open sourcenorfolkinfosec.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.