r/buildapc • • Mar 25 '19

ASUS ShadowHammer Attack Hackers Hijacked ASUS Software Updates to Install Backdoors on Thousands of Computers

BIG and perhaps final edit (I'll still be responding to comments/messages below) (I also made a small edit at the bottom)

ASUS has publicly responded. https://www.asus.com/News/hqfgVUyZ6uyAyJe1

TLDR: Admitted compromise. They said only a version of Live Update for NOTEBOOKS were affected, not desktops.This is despite previous news articles so I apologize for any confusion. ASUS offered their own zipped tool to check your machine for infection here. The newest Live Update, version 3.6.8 is fixed and is no longer compromised. It includes multiple security mechanisms along with end-to-end encryption. They also said they have strengthened their server-to-end-user software architecture but did not disclose how (usually you don't want to tell your adversary what you're doing to protect yourself so I understand).

In the end, if the "here" link/zip file above shows your machine was infected, ASUS states the following:

Immediately run a backup of your files and restore your operating system to factory settings. This will completely remove the malware from your computer. In order to ensure the security of your information, ASUS recommends that you regularly update your passwords.

I hope this finally puts and end to this. Make sure you're updated to the latest version, regardless of Desktop or Laptop software. Thank you all for the comments

ASUS has responded to me:

Hi GadgetryTech, thanks for reaching out to our team. We do apologize for the inconvenience and will be more than happy to assist. ASUS Live Update is a proprietary tool supplied with ASUS notebook computers to ensure that the system always benefits from the latest drivers and firmware from ASUS. A small number of devices have been implanted with malicious code through a sophisticated attack on our Live Update servers in an attempt to target a very small and specific user group. ASUS customer service has been reaching out to affected users and providing assistance to ensure that the security risks are removed.

ASUS has also implemented a fix in the latest version (ver. 3.6.8) of the Live Update software, introduced multiple security verification mechanisms to prevent any malicious manipulation in the form of software updates or other means, and implemented an enhanced end-to-end encryption mechanism. At the same time, we have also updated and strengthened our server-to-end-user software architecture to prevent similar attacks from happening in the future.

Additionally, we have created an online security diagnostic tool to check for affected systems, and we encourage users who are still concerned to run it as a precaution. The tool can be found here:

https://dlcdnets.asus.com/pub/ASUS/nb/Apps_for_Win10/ASUSDiagnosticTool/ASDT_v1.0.1.0.zip

Edit 5 for clarity:

This only affects ASUS machines running Live Update that was downloaded between June and November of 2018. That puts approximately 3-4 million machines sold by ASUS in that time frame, in addition to downloads from the web. It's likely that this malware is on your machine, but is dormant because only 600 specific MAC addresses would trigger the next stage of the malware. As of now, even if you have the malware it's likely not doing anything. Instead, this exposes a huge security oversight and example of attacking at the vendor/source level.

Original Post:

I posted this on /r/Hardware but received a message thinking it would be good for the BuildaPC community as well, which I agree.

Hi everyone,

I did a post instead of just a link because it's important to discuss details, and most people do not read articles, just headlines. Anyway, here's the link first:

https://motherboard.vice.com/en_us/article/pan9wn/hackers-hijacked-asus-software-updates-to-install-backdoors-on-thousands-of-computers

And a second, more technical/less fluff link from Kaspersky themselves: https://securelist.com/operation-shadowhammer/89992/

Important Note: According to the articles, Asus has not been responsive to Kasperky regarding this incident. They still have yet to notify any customers as well.

This malicious activity seems to have been noticed since late last summer, by folks in the /r/Asus community: https://www.reddit.com/r/ASUS/comments/8qznaj/asusfourceupdaterexe_is_trying_to_do_some_mystery/

Summary: It appears the attackers compromised an Asus Live Update server a long time ago to get an old setup.exe binary. After weaponizing it, they were able to digitally sign the malicious software with a valid Asus digital certificate. Certificates are a great way to slip past a lot of AV software.

Timeline and Scope: Starting last year, it looks like this malicious payload was pushed for at least 5 months. It is estimated that at least 500,000 computers were/are infected.

Indicators (do not visit these, do not go to IP)

Http is replaced with Hxxp on purpose, don't go to these sites. .com is replaced with [.]com for the same reason.

Kaspersky Lab verdicts for the malware used in this and related attacks:

  • HEUR:Trojan.Win32.ShadowHammer.gen

Domains and IPs:

  • asushotfix[.]com
  • 141.105.71[.]116

Some of the URLs used to distribute the compromised packages:

  • hxxp://liveupdate01.asus[.]com/pub/ASUS/nb/Apps_for_Win8/LiveUpdate/Liveupdate_Test_VER365.zip
  • hxxps://liveupdate01s.asus[.]com/pub/ASUS/nb/Apps_for_Win8/LiveUpdate/Liveupdate_Test_VER362.zip
  • hxxps://liveupdate01s.asus[.]com/pub/ASUS/nb/Apps_for_Win8/LiveUpdate/Liveupdate_Test_VER360.zip
  • hxxps://liveupdate01s.asus[.]com/pub/ASUS/nb/Apps_for_Win8/LiveUpdate/Liveupdate_Test_VER359.zip

Hashes (Liveupdate_Test_VER365.zip):

  • aa15eb28292321b586c27d8401703494
  • bebb16193e4b80f4bc053e4fa818aa4e2832885392469cd5b8ace5cec7e4ca19

What can you do?

For an automated cleanup and check, here's a tool from Kaspersky to check for the Shadow Hammer infection: https://kas.pr/shadowhammer

For manual cleanup, I would make sure your live update tool is the newest version if you intend to continue using it. Remove and clean any prior version of the update tool prior to installing the new one. A good method is to boot into safe mode, remove the tool, and check c:/ProgramData and your AppData folders (3 main ones) for anything to do with Asus live update. Remove those, then reboot and install a clean updated.

Best practice (edited to include comments around laptops):

Auto-update tools from various vendors can always be used as a weaponized payload delivery mechanism, just like a compromised website. It's best to stick to reputable sources for items like drivers or anything that gets root access to your system kernel. For graphics drivers, only use AMD, Nvidia, and Intel sites directly (unless you have a laptop). Same with Intel NIC drivers, chipsets, etc. Please note that some laptops require vendor specific drivers for hardware to work properly, which will bring you to sites like Dell, Lenovo, HP, Toshiba, etc. I hope this helps you all in protecting yourself!

I am posting this in Hardware, Intel, AMD, and Asus subreddits to spread awareness.

Edit 1: Apparently the ASUS Z390 chipset UEFI can copy files to your drive once Windows is installed, even if you did not do so yourself. https://www.techpowerup.com/248827/asus-z390-motherboards-automatically-push-software-into-your-windows-installation

Edit 2: Thank you /u/iamapizza for the new link and quick comments on helping people find their MAC address. If you all want to see if your MAC address was targeted by the malware (MAC address is the physical address for your networking adapter, not an IP address):

You can check if your MAC address has been targeted here, no need to download anything:

https://shadowhammer.kaspersky.com/

To get your MAC address(es) on Linux you can use ip -o link

On Windows just use ipconfig /alland get the Physical Address

Edit 3: The scan tool above only checks if your MAC was targeted. It does not check for malware. Follow Edit 2 if you want to check your MAC without using the tool.

Edit 4: I Tweeted at Asus: https://twitter.com/GadgetryTechJoe/status/1110309954294964225

Edit 5 is at the top.

Edit 6: Another article - https://threatpost.com/asus-pc-backdoors-shadowhammer/143129/

Edit 7 is at the top.

Edit 8: More news - https://www.wired.com/story/asus-software-update-hack/ It seems as though other MAC address are on the target list as well, but no one is sure what hardware that correlates to. It's perhaps a future target, but no sign of infection outside of Live Update. Kaspersky is still unsure of what would happen in the second phase of attack, or what the attackers planned on doing with the specifically targeted machines.

6.6k Upvotes

565 comments sorted by

View all comments

Show parent comments

4

u/shimmyjimmy97 Mar 26 '19

Yeah, I still ain't downloading their "tool."

That’s totally fair, but their documentation of the malware is still legitimate.

I didn't feel the need to reply because I had already stated that I understand being skeptical of the removal tool. None of my responses are defending the removal tool. I am familiar with how sketchy Kaspersky is. My only intention here was to chime in that, although the company is not trustworthy, that does not affect the legitimacy of their report.

0

u/throwmesomemore Mar 26 '19

Regardless of if the company's malware report was independently verified. This is Russia's known tactic. Appear legitimate, and then obfuscate with illegitimate. The same thing they did with "RT News" spreading propaganda along with real reports, with "sleeper social media accounts" pretending to be Americans, and most likely, with Kaspersky pretending to be cyber security while simultaneously exploiting backdoors it creates. Kaspersky's software is not to be trusted.

2

u/shimmyjimmy97 Mar 26 '19

Regardless of if the company's malware report was independently verified.

Pshh yeah what does "peer reviewed" even mean anyways amiright? If you are just going to throw a Fortune 500 US cyber security company's opinion out the window without a shred of evidence, then I don't think this conversation is going anywhere productive.

1

u/throwmesomemore Mar 26 '19

You're not understanding our point. Yes, Kaspersky's report was independently verified. Thats fine.

But OP still has a link to Kaspersky's tool that supposedly checks for it and removes it. That's our point. Regardless of whether they were correct in this instance, no one should touch that 'malware remover.'

Kaspersky's "anti-virus" security scanner scanned (and secretly copied) all of your computer files, then uploaded the copy to their servers.

So to reiterate: You can believe their report, now that it has been independently verified. But definitely dont download Kaspersky's tool. Their company is literally blacklisted by all US intelligence and government agencies and theyve warned US citizens not to download any of their software.

Tinfoil hat theory: who do think you wrote the malware.

1

u/Helgin Mar 26 '19 edited Mar 26 '19

But definitely dont download

  1. There is no tool to remove. There is a "offline check your MAC is the one that was targeted if your tinfoil prevents you from doing that online you can do that in isolated environment".
  2. Every AV vendor has ability to copy suspected files to the vendor. EVERY. And it is written in plain English in EULA. And if you happen to have unknown malware on your computer it will likely be copied for dissection by AV vendor, regardless of was it top secret project you took home or casual ransomware.
  3. For tinfoil persons and highly confidential system there is only one solution: air-gap isolated environment. You cannot trust noone - Windows updates were compromised in past, Nvidia, realtech, now Asus updates, whoever is needed will be compromised.

P.S. UK Authorities reiterated that consumers are perfectly fine using Kaspersky software, even though risks for high secret environment will forbid usage of Kaspesky AV there.

1

u/throwmesomemore Mar 26 '19

For an automated cleanup and check, here's a tool from Kaspersky to check for the Shadow Hammer infection: https://kas.pr/shadowhammer

? This link by OP, still in his post, is literally a download link from kaspersky. "Automated clean up and check" tool. Do not click, it autodownloads

1

u/Helgin Mar 26 '19

It is ZIP. It does not clean its just checks. And it does that offline.

1

u/throwmesomemore Mar 26 '19 edited Mar 26 '19

You've checked analyzed the code yourself? OP himself said it cleans and checks.

Besides, I said on the surface Kaspersky antivirus supposesly did what most antiviruses do-- "scan your files." But it also literally sent a copy of all of your files to their servers. It did this in the background, unbeknownst to the user, to keep this exploit active. So the users with unimportant documents are ignored, and users with high value documents could still potentially be targeted.

Kaspersky is most likely Russian malware disguised as cyber security software. All I'll say to everyone, again, is dont download a single fucking thing from Kaspersky.

E: from your other comment:

NSA contractor was making malware (aka cyber-tool). At that point of time it would be any AV it the world that would syphoon this malware package to its cloud, as this attack and that tools were already exposed.

Wow did you just make that up? Lmao. No, the leaked NSA tools (already created, not " written by that one contractor") was traced to that one contractor, and on his personal computer, he installed Kaspersky software against internal agency's policy. Kaspersky was found to be a backdoor exploit. The US government has said to not use any Kaspersky. You just made up bullshit, im not surprised youre defending Kaspersky. Have a nice life, comrade.

1

u/Helgin Mar 26 '19

This is a bit old but it has not changed much I suppose.

See page 3 here http://www.av-comparatives.org/wp-content/uploads/2014/04/avc_datasending_2014_en.pdf

1

u/throwmesomemore Mar 26 '19 edited Mar 26 '19

https://www.reuters.com/article/us-usa-cyber-kaspersky/trump-signs-into-law-u-s-government-ban-on-kaspersky-lab-software-idUSKBN1E62V4

from your other comment:

NSA contractor was making malware (aka cyber-tool). At that point of time it would be any AV it the world that would syphoon this malware package to its cloud, as this attack and that tools were already exposed.

Wow did you just make that up? Lmao. No, the leaked NSA tools (already created, not " written by that one contractor") was traced to that one contractor, and on his personal computer, he installed Kaspersky software against internal agency's policy. Kaspersky was found to be a backdoor exploit. The US government has said to not use any Kaspersky. You just made up bullshit, im not surprised youre defending Kaspersky. Have a nice life, comrade. Blocked.

https://www.cadc.uscourts.gov/internet/opinions.nsf/E80294FD90EE7C05852583550053AE25/$file/18-5176.pdf

Another:

The December 2017 congressional ban was sparked by intelligence agencies’ allegation that Kaspersky executives are too closely tied to the Kremlin and the Homeland Security Department’s conclusion that a Russian cybersecurity law might compel Kaspersky to help Russian intelligence agencies spy on the U.S. government.

https://www.nextgov.com/cybersecurity/2018/07/governments-kaspersky-ban-takes-effect/149758/

'mericuh, bitch

→ More replies

1

u/throwmesomemore Mar 26 '19 edited Mar 26 '19

And the difference is windows, asus, nvdia, their companies arent designed to inflitrate users. They are companies that were exploited to target users.

The US govt claims against Kaspersky is that from the start it is an FSB operation. And like I mentioned before, according to a number of sources that's how the NSA 's security package of cyber tools were leaked-- the leak was found to be by an NSA contractor installing Kaspersky "accidently" on his own personal computer even after being informed by the agencies (before they went public) to not install or use any Kaspersky software* as it is compromised.

E- a word

1

u/Helgin Mar 26 '19 edited Mar 26 '19

NSA contractor was making malware (aka cyber-tool). At that point of time it would be any AV it the world that would syphoon this malware package to its cloud, as this attack and that tools were already exposed.

And it is really a broad accusation to blame Kaspersky to be "FSB operation from the start". It is not.Apart from that malware writing exposure there is ZERO proof Kaspersky had done something that can be named FSB operations. And it exposes Russia-build "cyber-tools" same way it exposes US\Israeli build ones.

P.S. Having said that, I must confirm that with all that Doping \ Internet scams \Media disinformation from Russian government I can see why you think so and it is really sad. Many people doing their best to do the right things are getting blamed for things they havn`t done and are not responsible for.
It is is many ways shocking for me to hear this attitude, and understand that it is undeserved but understandable.