started · updated
Geekom admits to distributing malware-infected drivers via official website
Mini-PC manufacturer Geekom has admitted to distributing malware-infected network drivers through its official website. The compromised files, identified as the Asruex backdoor, were found within LAN driver packages for several AMD-based models, including the A7, A8, AE7, AE8, AX7 Pro, and AX8 Pro.
Geekom explained that the malware was hosted on an obsolete support page that had been replaced in the main navigation but remained indexed by search engines. This allowed users searching via Google or AI assistants to download the malicious files directly from the official domain. The Asruex malware is capable of granting attackers remote administrative access, stealing sensitive data, and logging keystrokes.
The company has since removed the affected files and issued a public apology. Geekom clarified that the malware was not pre-installed on the devices' operating systems and that current support pages are secure. Users who may have downloaded the infected drivers are advised to run a full system scan with Windows Defender or perform a clean installation of Windows to ensure security.
Entities
AMD · Asruex · Geekom · Realtek · VideoCardz