Jump to content

ShadowHammer Asus distributes malware to thousands of computers

lacion
2 hours ago, captain_to_fire said:

So it seems that last year some users discovered a shady Asus update which was discussed in this subreddit. 

It remained undetected by every antivirus until Kaspersky updated their detection algorithms to detect supply chain anomalies. I don’t see any reason why Asus would force Kaspersky to sign a NDA and not inform their users about a malicious update that hitchhiked their supply chain. 

 

yeah I posted the reddit link a few posts back. they mention it in the article.

 

the reason why the try to force an NDA for this is antiquated management practices. they believe if they keep it quiet no one will notice. or if details about their security practices are secrets and no one knows them it makes things more secure.

 

this is probably why they do things like NDA https://en.wikipedia.org/wiki/Security_through_obscurity

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×