Recently, Kaspersky Lab revealed an unusual cyberattack that may have affected around a million users of ASUS portable and desktop computers. The investigation showed that cybercriminals added a backdoor to the ASUS Live Update utility, which is used for updating BIOS, UEFI, and software for motherboards and laptops from the Taiwanese company. Following this, the attackers organized the distribution of the modified utility through official channels.

ASUS confirmed this fact by publishing a special press release regarding the attack. According to the manufacturer's official statement, Live Update—a software update tool for the company's devices—was subjected to APT (Advanced Persistent Threat) attacks. The term APT is used in the industry to describe state-sponsored hackers or, less commonly, highly organized criminal groups.
A small number of devices were infected with malware through a sophisticated attack on our servers Live Update in an attempt to target a very small and specific group of users, ASUS's press release states. ASUS support is working with affected users and providing assistance to mitigate the security threats.

The term 'small number' somewhat contradicts the information from Kaspersky Lab, which claimed it found malware (called ShadowHammer) on 57,000 computers. Meanwhile, security experts estimate that many other devices could also have been compromised.
In the press release, ASUS stated that the backdoor has been removed from the latest version of the Live Update utility. ASUS also reported that it provided comprehensive encryption and additional security check tools to protect customers. Furthermore, ASUS has developed a tool that it claims will determine whether a particular system was compromised and has encouraged concerned users to contact its support.
The attack reportedly occurred in 2018 over at least five months, and Kaspersky Lab discovered the backdoor in January 2019.

Source: 3dnews.ru
