ELSEIF
Your brief EB
338 stories from 110 feeds 374 clusters Refreshed 56 seconds ago next pull 20:07

SECURITY Signal 410

Geekom admits shipping malware-laced AMD mini-PC network drivers and removes infected package

Geekom confirmed its legacy LAN driver installer for select AMD mini-PCs contained the Asruex backdoor malware and has since withdrawn the package.

WHY IT MATTERS

Malware embedded in a driver installer gains administrator-level access, enabling data theft, keystroke logging, and remote control. Engineers deploying or supporting these mini-PCs must verify driver sources and consider full system wipes for affected machines. The incident underscores the risk of relying on manufacturer websites for driver updates, even from legitimate vendors.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

Geekom’s legacy LAN driver installer for A7, A8, AE7, AE8, AX7 Pro, and AX8 Pro mini-PCs contained the Asruex backdoor malware.

02

The infected driver was removed from Geekom’s support site, but the page remained accessible via search engines.

03

Malware in the installer granted administrator privileges, allowing data exfiltration and remote command-and-control access.

THE READ

What the cluster adds up to.

ORIGINAL ANALYSIS

Geekom acknowledged that a legacy LAN driver installer for its AMD-based mini-PCs was compromised with the Asruex backdoor malware. The driver was hosted on a support page that had been replaced but remained indexed by search engines, increasing the likelihood of unintended downloads. The company removed the infected package after the issue was reported, but the initial response included a request for the reporting outlet to retract its coverage, which was denied.

The malware’s presence in a driver installer is particularly concerning because drivers run with elevated privileges. This grants the malware full access to the system, enabling actions like data theft, keystroke logging, and establishing persistent remote access via command-and-control servers. Engineers managing these mini-PCs should treat any system that installed the driver as potentially compromised, with a full wipe being the most reliable mitigation.

The incident highlights the risks of sourcing drivers from manufacturer websites, even for legitimate hardware. While Windows Update is the recommended source for drivers, users often turn to OEM sites for the latest versions or to troubleshoot issues. The fact that the infected driver was on a legacy page, still discoverable via search, demonstrates how easily such threats can persist. Corroboration by multiple malware detection engines confirms the threat was real, not a false positive.

This case mirrors past incidents where malware was distributed via official channels, such as AceMagic’s factory-shipped malware or Asus’ compromised software updates. Unlike those examples, Geekom’s mini-PCs were not infected out-of-the-box, but the driver’s availability on a legacy page created a similar risk. The event serves as a reminder that even trusted vendors can inadvertently distribute malware, and engineers must verify driver integrity before installation.

Written by elseif from the cluster below · checked for specifics the sources never contained

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
Tomshardware Geekom admits to shipping malware-laced network drivers for AMD mini PCs — company responds with guidance, removes malicious package Open ↗