ASUS Releases Fix For ShadowHammer Malware Attack

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12LkWCHvGPsY_cpc4X_FCK7-gPUBNwiZmfz9uU8+UuY_qw@mail.gmail.com>
'ASUS may have inadvertently pushed malware to some of its computers
through its update tool, but it at least it has a fix ready to go. The
PC maker has released a new version of its Live Update software for
laptops that addresses the ShadowHammer backdoor attack. It also
promised "multiple security verification mechanisms" to reduce the
chances of further attacks, and started using an "enhanced end-to-end
encryption mechanism." There are upgrades to the behind-the-scenes
server system to prevent future attacks, ASUS added.

The company simultaneously reiterated the narrow scope of
ShadowHammer, noting that the malware targeted a "very small and
specific user group." It's believed to be an Advanced Persistent
Threat -- that is, a state-backed assault against organizations rather
than everyday users. Other ASUS devices weren't affected, according to
a notice. While the fix is reassuring, it also raises questions as to
why the systems weren't locked down earlier. Update tools are prime
targets for hackers precisely because they're both trusted and have
deep access to the operating system -- tight security is necessary to
prevent an intruder from hijacking the process.'

-- source: https://hardware.slashdot.org/story/19/03/26/2025229

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.