The list of nearly 600 MAC addresses was targeted in the recent hacking of millions of ASUS computer users
While revealing details about the widespread cyberattack targeting large supply chains for ASUS customers (ASUS Supply Chain Attack), Russian security company Kaspersky last week did not publish the full list of All MAC addresses that hackers have encrypted into their malware to target specific user groups.
Instead, Kaspersky has released a dedicated offline tool, and also launched an online website where users of ASUS computers can search the device's MAC address for testing. Check if you are on the affected list at the address:
https://shadowhammer.kaspersky.com/
- Hackers take control of the update tool, attacking tens of thousands of ASUS computers
However, many people believe that this is not really a convenient option for large enterprises with hundreds of thousands of devices in the system, if conducting manual search as with individual users, it is too lost. time. Hopefully Kaspersky will offer a method to find more effective MAC addresses for businesses in the future.
List of targeted MAC addresses in ASUS Supply Chain Attack
To help address the raid issues, and at the same time to help other cyber security experts continue to hunt for relevant hacking campaigns, Australian security company Skylight has decided to provide a full list Enough of nearly 583 MAC addresses were targeted in the ASUS server attack to send malicious code, according to the statistics performed.
- The alarming increase in the number of attacks targeted at IoT devices
'I think that if the information related to the hacked targets has been compiled, it should be provided publicly to the security community to help us better protect ourselves. So Skylight thinks that extracting the list of MAC addresses is targeted in the ASUS Supply Chain Attack, and publicizing it so everyone can conduct the necessary comparisons on their own ASUS device. Knowing in your domain will be a great idea at this time, 'said Shahar Zini, CTO of security company Skylight.
Accordingly, Skylight's security researchers successfully extracted the list of targeted MAC addresses with the help of the offline search engine released by Kaspersky, which contains the complete list of 619. The MAC address is in the executable file, but is protected by salted hash algorithm.
Specifically, Skylight experts used a powerful Amazon server combination and a modified version of the HashCat password cracking tool to successfully extract 583 MAC addresses in less than an hour.
'We took advantage of Amazon's AWS p3.16xlarge server. This 'monster' carries within itself 8 NVIDIA V100 Tesla 16GB GPUs. All 1300 prefixes have been brute force in less than an hour, "the Skylight team said.
You can access the target MAC address list extracted by Skylight at the following address:
https://skylightcyber.com/2019/03/28/unleash-the-hash-shadowhammer-mac-list/list.txt
- Endpoint Detection and Response threats, an emerging security technology
The hack on ASUS: Operation Shadow Hammer
Last week, a sponsored group of hackers tried to hijack the ASUS Live automatic update software server (launched last year) and pushed malicious updates to more than a million Windows computers. worldwide to infect them into backdoor systems. Kaspersky Lab calls this attack "Operation ShadowHammer" and it takes place from mid-June to November 2018, possibly affecting more than 1 million ASUS users worldwide, including more than 57,000 users. install Kaspersky computer saver.
The Russian security company later informed ASUS of this ongoing supply chain attack campaign on January 31, 2019.
After analyzing more than 200 malicious updates, Kaspersky researchers have identified attackers (not yet attributed to any APT group) that really want to target only a specific list of users. These are identified by their unique MAC addresses, and these addresses are hard-coded into malware.
Although in phase 2, malware is only pushed to nearly 600 targeted users, but that doesn't mean that millions of ASUS computers have received updates to be "immune" to the category. malicious code used in this attack campaign.
- Fileless malware - Achilles heel of traditional antivirus software
How to check if your ASUS laptop has been hacked?
After admitting that his server was successfully hacked by an unidentified hackers between June and November 2018, ASUS released a completely clean new version earlier this week. of LIVE Update application (version 3.6.8) and also promises to add "multiple security verification mechanisms" to limit hackers' attack capabilities.
- What is cybercrime? How to prevent cybercrime?
However, you should also know that installing only the updated version will not help remove malicious code from thoroughly infected systems. Therefore, to help their customers determine if they are a victim of this attack, ASUS has also released a diagnostic tool that you can use to check if the system Is my ASUS affected by a malicious update that hackers spread earlier. You can download this tool at the following address:
https://dlcdnets.asus.com/pub/ASUS/nb/Apps_for_Win10/ASUSDiagnosticTool/ASDT_v1.0.1.0.zip
If you find your computer's MAC address in the list, that means the device has been backed up by a malicious update and ASUS recommends that you restore the original settings to wipe the entire code. exclusive on the system.
You should read it
- ASUS calls for revolutionizing computer design
- What's new in Asus' new mini GPU?
- Asus super device to Vietnam
- The first two laptops use Asus 3.0 USB 3.0
- Instructions for Hard Reset ASUS ZENFONE 5 (Part 2)
- Asus VivoBook S15 review: A great, comprehensive experience
- Opponent of Asus computer
- ASUS to the Zenbook NX500 high-end laptop, 4K screen
May be interested
- Learn about Ethical hacking using Kali Linux and Raspberry Pia raspberry pi 3 runs kali linux for building amazing hacking skills. this small computer is cheap, powerful and very flexible.
- Laptop price points reduced by millionsin the past two months, there have been a series of laptops with millions of dong discount, in which laptops from acer, hp and asus are the strongest heat-reducing products.
- What is hardware hacking? Is it worrisome?hardware hacking involves exploiting vulnerabilities in the physical components of a device. unlike software hacking, attackers must be on-site and need physical - and reasonably uninterrupted - access to the target device to perform a hardware hack.
- Asus Laptops get a series of design awardsat the recent bmw welt exhibition, asus has won nine prestigious design awards if design award 2013.
- Asus VivoBook S15 review: A great, comprehensive experienceasus vivobook s15 laptop (model s533) is one of the highly anticipated computers, as previous vivobooks have really made a good impression on users. indeed, this is one of the best windows 10 laptops you can use at the moment.
- How to Avoid Post-Tracking Targeted Ads After Shopping Onlinelet's face it — targeted ads can be annoying, persistent, and seemingly impossible to escape as they follow you around the web. luckily, there are ways to minimize their intrusiveness and reclaim your online experience.
- Hackers take control of the update tool, attacking tens of thousands of ASUS computershackers have taken control of the upgrade tool - asus live update utility is preinstalled on the vast majority of asus new devices and silently installs malware on devices.
- How to find available IP addressesfinding an available ip address is useful if you need to connect devices such as printers, computers, game consoles (like xbox 360) or dvrs to the network.
- The best way to install drivers for ASUS computer- like other laptops, asus also provides users with driver download pages.
- Laptop Apple and Asus are the most stable in the USsurvey of rescuecom computer hospital in the us said that the number of calls for technical support of apple and asus users in the second quarter at least