Geekom acknowledged that a Realtek LAN driver package hosted on a legacy support page for several AMD-based mini PCs was infected with the Asruex backdoor/Trojan. Reported affected models include the A7, A8, AE7, AE8, AX7 Pro, and AX8 Pro. The malicious installer was reportedly still reachable through search engine indexing even after Geekom replaced its older support system, allowing users to download what appeared to be a legitimate vendor driver from the company’s website.
Because the malware was embedded in a driver installer, it could execute with elevated privileges and enable remote access, data theft, keystroke capture, and password theft. Geekom said there is no indication systems shipped infected out of the box and that the exposure is limited to users who downloaded and ran the legacy package. The company removed the file and said it is reviewing obsolete support resources, while guidance to affected users includes deleting the installer, scanning systems, reinstalling drivers from trusted current sources, and in higher-risk cases performing a full system wipe or an offline Microsoft Defender scan.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
Both reports state that Geekom asked VideoCardz to consider removing its original reporting, but VideoCardz declined. The outlet maintained the report after Geekom confirmed the issue.
Geekom apologized to users and advised anyone who downloaded the installer to delete it and avoid running it. Users who executed it were told to run a full anti-malware scan, replace the driver from trusted sources, and in higher-risk cases consider a clean Windows reinstall or full system wipe.
After the issue was identified, Geekom said it removed the malicious software package and was removing the obsolete files and pages associated with the incident. The company also said it was reviewing or tightening support-resource management procedures.
Geekom acknowledged that the malicious driver package was hosted on an outdated support resource that had been replaced and was no longer reachable through normal navigation, though it remained indexed by search engines. The company said its pre-installed Windows images did not include the flagged file, indicating the issue was tied to the downloadable package rather than out-of-box infection.
The reporting says VideoCardz validated the presence of Asruex in the driver package using VirusTotal, FileScan.IO, MetaDefender, and Yarafy. This confirmed the installer was malicious rather than a false alarm.
VideoCardz discovered that a downloadable Geekom Realtek/LAN driver package hosted on a legacy support page was infected with the Asruex backdoor. The affected exposure applied to users who downloaded and executed the installer from Geekom's website, not to factory-shipped systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcetomshardware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.