• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Asus Motherboard Owners: Do you have updater installed?

Joined
Mar 10, 2015
Messages
3,984 (1.20/day)
System Name Wut?
Processor 3900X
Motherboard ASRock Taichi X570
Cooling Water
Memory 32GB GSkill CL16 3600mhz
Video Card(s) Vega 56
Storage 2 x AData XPG 8200 Pro 1TB
Display(s) 3440 x 1440
Case Thermaltake Tower 900
Power Supply Seasonic Prime Ultra Platinum
Looks like their updater may have been compromised.

https://motherboard.vice.com/en_us/...o-install-backdoors-on-thousands-of-computers

Edit: In case you don't read it, you were likely not a target.

Edit 2:

It does seem like they have been unresponsive and reportedly not notified any customers. Although considering the highly targeted nature, I'm not sure if it matters but pretty rotten not to let people know about it.

Kamluk said Kaspersky notified ASUS of the problem on January 31, and a Kaspersky employee met with ASUS in person on February 14. But he said the company has been largely unresponsive since then and has not notified ASUS customers about the issue.

The attackers used two different ASUS digital certificates to sign their malware. The first expired in mid-2018, so the attackers then switched to a second legitimate ASUS certificate to sign their malware after this.

Kamluk said ASUS continued to use one of the compromised certificates to sign its own files for at least a month after Kaspersky notified the company of the problem, though it has since stopped. But Kamluk said ASUS has still not invalidated the two compromised certificates, which means the attackers or anyone else with access to the un-expired certificate could still sign malicious files with it, and machines would view those files as legitimate ASUS files.
 
Last edited:
Joined
Mar 23, 2016
Messages
4,839 (1.64/day)
Processor Ryzen 9 5900X
Motherboard MSI B450 Tomahawk ATX
Cooling Cooler Master Hyper 212 Black Edition
Memory VENGEANCE LPX 2 x 16GB DDR4-3600 C18 OCed 3800
Video Card(s) XFX Speedster SWFT309 AMD Radeon RX 6700 XT CORE Gaming
Storage 970 EVO NVMe M.2 500 GB, 870 QVO 1 TB
Display(s) Samsung 28” 4K monitor
Case Phantek Eclipse P400S (PH-EC416PS)
Audio Device(s) EVGA NU Audio
Power Supply EVGA 850 BQ
Mouse SteelSeries Rival 310
Keyboard Logitech G G413 Silver
Software Windows 10 Professional 64-bit v22H2
Neowin said:
To bypass detection by major security solutions, the hackers signed the modified versions of the utility with legitimate digital certificates stolen from ASUS and pushed the trojanized system to the firm's update servers.

According to Kaspersky's findings, each backdoor code has a list of MAC addresses that would scan for a device's unique MAC address and download a malicious payload onto the computer once a match has been found. Out of the hundreds of thousands of potentially affected devices, only 600 specific MAC addresses were targeted by the malware.

Kaspersky researchers also found three other vendors based in Asia whose software was infected with the same backdoor.

The company discovered the malware in January and has since reported it to ASUS and the three other unnamed vendors. Full details of ShadowHammer will be presented at Security Analyst Summit 2019 in Singapore from April 9 to 11.
https://www.neowin.net/news/asus-up...ackdoor-potentially-affecting-1-million-users
 

Space Lynx

Astronaut
Joined
Oct 17, 2014
Messages
15,929 (4.59/day)
Location
Kepler-186f
don't forget to install their RGB software too! trust us!
 

FreedomEclipse

~Technological Technocrat~
Joined
Apr 20, 2007
Messages
23,364 (3.76/day)
Location
London,UK
System Name Codename: Icarus Mk.VI
Processor Intel 8600k@Stock -- pending tuning
Motherboard Asus ROG Strixx Z370-F
Cooling CPU: BeQuiet! Dark Rock Pro 4 {1xCorsair ML120 Pro|5xML140 Pro}
Memory 32GB XPG Gammix D10 {2x16GB}
Video Card(s) ASUS Dual Radeon™ RX 6700 XT OC Edition
Storage Samsung 970 Evo 512GB SSD (Boot)|WD SN770 (Gaming)|2x 3TB Toshiba DT01ACA300|2x 2TB Crucial BX500
Display(s) LG GP850-B
Case Corsair 760T (White)
Audio Device(s) Yamaha RX-V573|Speakers: JBL Control One|Auna 300-CN|Wharfedale Diamond SW150
Power Supply Corsair AX760
Mouse Logitech G900
Keyboard Duckyshine Dead LED(s) III
Software Windows 10 Pro
Benchmark Scores (ノಠ益ಠ)ノ彡┻━┻
I dont use any Asus software with my Asus board other than. the lighting thing that doesnt even work half the god. damn. time.
 
Joined
Mar 23, 2016
Messages
4,839 (1.64/day)
Processor Ryzen 9 5900X
Motherboard MSI B450 Tomahawk ATX
Cooling Cooler Master Hyper 212 Black Edition
Memory VENGEANCE LPX 2 x 16GB DDR4-3600 C18 OCed 3800
Video Card(s) XFX Speedster SWFT309 AMD Radeon RX 6700 XT CORE Gaming
Storage 970 EVO NVMe M.2 500 GB, 870 QVO 1 TB
Display(s) Samsung 28” 4K monitor
Case Phantek Eclipse P400S (PH-EC416PS)
Audio Device(s) EVGA NU Audio
Power Supply EVGA 850 BQ
Mouse SteelSeries Rival 310
Keyboard Logitech G G413 Silver
Software Windows 10 Professional 64-bit v22H2
the lighting thing that doesnt even work half the god. damn. time.
Asus's Q&A for software is lacking in quality? No one should be expecting much from any of the name brands.
 
Joined
Mar 24, 2010
Messages
5,047 (0.98/day)
Location
Iberian Peninsula
whats for sure is their Update never updated a fook!
 
Joined
Jan 4, 2017
Messages
431 (0.16/day)
Location
Ohio
This is sounding very nation-statey. Not to bring out the tinfoil hats, but using legitimate certs nefariously seems to be a signature move for advanced persistent threat actors. The targeted nature of the additional payloads also supports this. I think most people are fixated on how poorly ASUS is handling this (legitimate point), but not how scary this seems to be (to me at least).
 

DeaconFrost

New Member
Joined
Mar 27, 2019
Messages
9 (0.00/day)
System Name SKTOWER01
Processor AMD Ryzen 7 2700X
Motherboard ASUS ROG Strix X470-F Gaming
Cooling AMD Wraith Prism RGB
Memory Corsair Vengeance LPX 32 GB
Video Card(s) eVGA GTX 1060 6 GB
Storage Samsung 960 Pro 512 GB m.2 | Samsung 860 Evo 1 TB m.2 | Seagate FireCuda 2 TB SATA
Display(s) Samsung LS27D590CS/ZA
Case Corsair Crystal 460X
Power Supply Corsair CX750M
Software Windows 10 Pro x64
I've had mine running for a few months, and has yet to find an update. BIOS updates are done through the actual BIOS (for me), so I'm thinking of removing the utility completely. I could never find a way to stop it from running at boot, either. That alone makes me not a fan.
 
Joined
Mar 24, 2010
Messages
5,047 (0.98/day)
Location
Iberian Peninsula
when you uninstall Asus software you still have to check and delete some Folders, Services, Autoruns, and Task Scheduler. Apart from creating "Asus" folders everywhere, they also put a "LightingService" folder out in the open of the main Program folder... etc etc etc
 
Top