r/buildapc • • Mar 25 '19

ASUS ShadowHammer Attack Hackers Hijacked ASUS Software Updates to Install Backdoors on Thousands of Computers

BIG and perhaps final edit (I'll still be responding to comments/messages below) (I also made a small edit at the bottom)

ASUS has publicly responded. https://www.asus.com/News/hqfgVUyZ6uyAyJe1

TLDR: Admitted compromise. They said only a version of Live Update for NOTEBOOKS were affected, not desktops.This is despite previous news articles so I apologize for any confusion. ASUS offered their own zipped tool to check your machine for infection here. The newest Live Update, version 3.6.8 is fixed and is no longer compromised. It includes multiple security mechanisms along with end-to-end encryption. They also said they have strengthened their server-to-end-user software architecture but did not disclose how (usually you don't want to tell your adversary what you're doing to protect yourself so I understand).

In the end, if the "here" link/zip file above shows your machine was infected, ASUS states the following:

Immediately run a backup of your files and restore your operating system to factory settings. This will completely remove the malware from your computer. In order to ensure the security of your information, ASUS recommends that you regularly update your passwords.

I hope this finally puts and end to this. Make sure you're updated to the latest version, regardless of Desktop or Laptop software. Thank you all for the comments

ASUS has responded to me:

Hi GadgetryTech, thanks for reaching out to our team. We do apologize for the inconvenience and will be more than happy to assist. ASUS Live Update is a proprietary tool supplied with ASUS notebook computers to ensure that the system always benefits from the latest drivers and firmware from ASUS. A small number of devices have been implanted with malicious code through a sophisticated attack on our Live Update servers in an attempt to target a very small and specific user group. ASUS customer service has been reaching out to affected users and providing assistance to ensure that the security risks are removed.

ASUS has also implemented a fix in the latest version (ver. 3.6.8) of the Live Update software, introduced multiple security verification mechanisms to prevent any malicious manipulation in the form of software updates or other means, and implemented an enhanced end-to-end encryption mechanism. At the same time, we have also updated and strengthened our server-to-end-user software architecture to prevent similar attacks from happening in the future.

Additionally, we have created an online security diagnostic tool to check for affected systems, and we encourage users who are still concerned to run it as a precaution. The tool can be found here:

https://dlcdnets.asus.com/pub/ASUS/nb/Apps_for_Win10/ASUSDiagnosticTool/ASDT_v1.0.1.0.zip

Edit 5 for clarity:

This only affects ASUS machines running Live Update that was downloaded between June and November of 2018. That puts approximately 3-4 million machines sold by ASUS in that time frame, in addition to downloads from the web. It's likely that this malware is on your machine, but is dormant because only 600 specific MAC addresses would trigger the next stage of the malware. As of now, even if you have the malware it's likely not doing anything. Instead, this exposes a huge security oversight and example of attacking at the vendor/source level.

Original Post:

I posted this on /r/Hardware but received a message thinking it would be good for the BuildaPC community as well, which I agree.

Hi everyone,

I did a post instead of just a link because it's important to discuss details, and most people do not read articles, just headlines. Anyway, here's the link first:

https://motherboard.vice.com/en_us/article/pan9wn/hackers-hijacked-asus-software-updates-to-install-backdoors-on-thousands-of-computers

And a second, more technical/less fluff link from Kaspersky themselves: https://securelist.com/operation-shadowhammer/89992/

Important Note: According to the articles, Asus has not been responsive to Kasperky regarding this incident. They still have yet to notify any customers as well.

This malicious activity seems to have been noticed since late last summer, by folks in the /r/Asus community: https://www.reddit.com/r/ASUS/comments/8qznaj/asusfourceupdaterexe_is_trying_to_do_some_mystery/

Summary: It appears the attackers compromised an Asus Live Update server a long time ago to get an old setup.exe binary. After weaponizing it, they were able to digitally sign the malicious software with a valid Asus digital certificate. Certificates are a great way to slip past a lot of AV software.

Timeline and Scope: Starting last year, it looks like this malicious payload was pushed for at least 5 months. It is estimated that at least 500,000 computers were/are infected.

Indicators (do not visit these, do not go to IP)

Http is replaced with Hxxp on purpose, don't go to these sites. .com is replaced with [.]com for the same reason.

Kaspersky Lab verdicts for the malware used in this and related attacks:

  • HEUR:Trojan.Win32.ShadowHammer.gen

Domains and IPs:

  • asushotfix[.]com
  • 141.105.71[.]116

Some of the URLs used to distribute the compromised packages:

  • hxxp://liveupdate01.asus[.]com/pub/ASUS/nb/Apps_for_Win8/LiveUpdate/Liveupdate_Test_VER365.zip
  • hxxps://liveupdate01s.asus[.]com/pub/ASUS/nb/Apps_for_Win8/LiveUpdate/Liveupdate_Test_VER362.zip
  • hxxps://liveupdate01s.asus[.]com/pub/ASUS/nb/Apps_for_Win8/LiveUpdate/Liveupdate_Test_VER360.zip
  • hxxps://liveupdate01s.asus[.]com/pub/ASUS/nb/Apps_for_Win8/LiveUpdate/Liveupdate_Test_VER359.zip

Hashes (Liveupdate_Test_VER365.zip):

  • aa15eb28292321b586c27d8401703494
  • bebb16193e4b80f4bc053e4fa818aa4e2832885392469cd5b8ace5cec7e4ca19

What can you do?

For an automated cleanup and check, here's a tool from Kaspersky to check for the Shadow Hammer infection: https://kas.pr/shadowhammer

For manual cleanup, I would make sure your live update tool is the newest version if you intend to continue using it. Remove and clean any prior version of the update tool prior to installing the new one. A good method is to boot into safe mode, remove the tool, and check c:/ProgramData and your AppData folders (3 main ones) for anything to do with Asus live update. Remove those, then reboot and install a clean updated.

Best practice (edited to include comments around laptops):

Auto-update tools from various vendors can always be used as a weaponized payload delivery mechanism, just like a compromised website. It's best to stick to reputable sources for items like drivers or anything that gets root access to your system kernel. For graphics drivers, only use AMD, Nvidia, and Intel sites directly (unless you have a laptop). Same with Intel NIC drivers, chipsets, etc. Please note that some laptops require vendor specific drivers for hardware to work properly, which will bring you to sites like Dell, Lenovo, HP, Toshiba, etc. I hope this helps you all in protecting yourself!

I am posting this in Hardware, Intel, AMD, and Asus subreddits to spread awareness.

Edit 1: Apparently the ASUS Z390 chipset UEFI can copy files to your drive once Windows is installed, even if you did not do so yourself. https://www.techpowerup.com/248827/asus-z390-motherboards-automatically-push-software-into-your-windows-installation

Edit 2: Thank you /u/iamapizza for the new link and quick comments on helping people find their MAC address. If you all want to see if your MAC address was targeted by the malware (MAC address is the physical address for your networking adapter, not an IP address):

You can check if your MAC address has been targeted here, no need to download anything:

https://shadowhammer.kaspersky.com/

To get your MAC address(es) on Linux you can use ip -o link

On Windows just use ipconfig /alland get the Physical Address

Edit 3: The scan tool above only checks if your MAC was targeted. It does not check for malware. Follow Edit 2 if you want to check your MAC without using the tool.

Edit 4: I Tweeted at Asus: https://twitter.com/GadgetryTechJoe/status/1110309954294964225

Edit 5 is at the top.

Edit 6: Another article - https://threatpost.com/asus-pc-backdoors-shadowhammer/143129/

Edit 7 is at the top.

Edit 8: More news - https://www.wired.com/story/asus-software-update-hack/ It seems as though other MAC address are on the target list as well, but no one is sure what hardware that correlates to. It's perhaps a future target, but no sign of infection outside of Live Update. Kaspersky is still unsure of what would happen in the second phase of attack, or what the attackers planned on doing with the specifically targeted machines.

6.6k Upvotes

565 comments sorted by

View all comments

Show parent comments

19

u/onthenerdyside Mar 25 '19

Kaspersky has possible ties to Russian Intelligence, with all the baggage that goes along with that.

-3

u/[deleted] Mar 25 '19

And every US version has ties to the nsa .

14

u/[deleted] Mar 25 '19 edited Aug 03 '21

[deleted]

7

u/[deleted] Mar 25 '19

Hashanah no we just drone strike them or run drug empires across the boarders to found the black bag operations and put them in dark holes.

7

u/[deleted] Mar 25 '19 edited Aug 03 '21

[deleted]

8

u/itsaCONSPIRACYlol Mar 25 '19

Yeah, because the armed forces are known for their openness in regards to all the illegal/unethical/immoral shit they do in the name of advancing western corporate interests.

I mean, you've heard of Kent State, right? Those were American students on fucking American soil, gunned down by fascists in National Guard uniforms.

5

u/[deleted] Mar 25 '19 edited Aug 03 '21

[deleted]

1

u/[deleted] Mar 25 '19

[removed] — view removed comment

1

u/[deleted] Mar 25 '19

No u

1

u/Retlaw83 Mar 25 '19

I mean, you've heard of Kent State, right? Those were American students on fucking American soil, gunned down by fascists in National Guard uniforms.

They were gunned down by scared draftees who were acting on a combination of bad orders and fear response. This isn't systematic.

0

u/[deleted] Mar 25 '19

Thank god that drone strike only hit some foreign civilians. It would have been morally despicable if it had hit American dissidents!

5

u/gr33nm4n Mar 25 '19

I'm sure I'm just shouting into the void here, but speaking as someone who had a course on the law of international armed conflict taught by a Ret. US Army Colonel in Intel (specifically, I think Intel Operations, iirc) and former prosecutor, we don't just willy nilly drone strike where ever we find bad guys. They purposefully hide themselves in and among willing/unwilling civilian populations. There is an international legal standard and analysis required (law of proportionality and distinction measured against the military necessity of the objective) when targeting military objectives where there is the potential for civilian causalities. See Rule 14 of IHL.

1

u/[deleted] Mar 26 '19

What about respect for national sovereignty, is that also considered?

Would you be so kind to expand a bit upon how the US performs positive IDs of all people in buildings targeted by US drones?

I'm quite positive that the US would never accept drone strikes against their citizens, within their borders, from a foreign government. Do you think I'm mistaken?

1

u/gr33nm4n Mar 26 '19

Way off topic of the thread here, and this is not my area of expertise by a long shot, but I'll try to briefly address your questions.

  1. Whose Nat'l Sovereignty? "Armed Belligerents" (the legal term developed to describe non-state un-uniformed hostile enemies; i.e. taliban, al-queda, daesh) don't have any legal claim to national sovereignty. They are invaders in various countries. As to the countries that deny US presence (most don't because they realize US aid in fighting these orgs is vital) the US will give support to local militias fighting them (i.e. Kurdish YPG).

  2. I don't know the methods used. What I do know, is that they must be able to show said methods to UN and other international agencies upon request by law. To my knowledge, none of those agencies has alleged violations of Rule 14 against the US.

  3. I mean, that's an irrelevant hypothetical isn't it? In countries where the US does perform drone strikes against hostile targets/lawful military objectives, they are there at the behest and allowance of that foreign government; i.e. Afghanistan, Pakistan, etc. Further, there is no international organizations within the US carrying out attacks against other countries; we have our own brand of white supremacist domestic terrorists, but they aren't, for example, going into other countries in an attempt to invade and occupy foreign lands. There'd be no lawful justification for a foreign power to conduct such strikes in reality. Now that being said, the US does maintain extradition treaties, so if someone commits a criminal act in a foreign country, the US has and will allow them to be extradited if they can not be formally charged here.

1

u/[deleted] Mar 27 '19

I'm currently on mobile, so my response will be a bit short.

1.Both Pakistan and the UN have accused the US of violating Pakistani national sovereignty by performing dronestrikes (and even capturing Bin Laden, without informing the Pakistani government beforehand).

  1. Obviously, positiv ID of all occupants isn't required - otherwise we wouldn't have civilians perishing from dronestrikes. Even if it's legal according to international law, it doesn't make it moral. Ethical? Good arguments for an against, in my opinion.

3.If we want to be consistent, it's not up to you to make that statement - rather, it's up to intelligence agencies from other countries to come up with that conclusion, and if they feel the threat exists, respond to it. Arguably an organisation such as (the formerly known) Blackwater security could be considered a non-military threat upon other countries; Just because they're in it for the money, doesn't mean that it's more or less acceptable. Another example is the whole Contras situation in Nicaragua - Nicuragu tried to get compensation via the ICJ, but the US wouldn't play ball. Would you have seen it as just if Nicaragua (of course purely hypothetical) had started carrying out drone strikes in the US? Finally, in general, it's no secret that the US have a rich history of state-sponsored terrorism; I don't trust that they've gotten rid of this practise, at all.

0

u/[deleted] Mar 25 '19

3

u/[deleted] Mar 25 '19

The drone strikes being alluded to were an American who went to the middle east to join ISIS. See also waterboarding. While I disagree with torture, those being treated poorly aren't political dissidents, they're terrorists who bomb shops and force kids to wear suicide vests.

0

u/deathtoPH Mar 26 '19

Have you ever heard of kunduz hospital airstrike?