Newly discovered supply chain attack that leveraged ASUS Live Update software. The goal of the attack was to surgically target an unknown pool of users, which were identified by their network adapters’ MAC addresses. To achieve this, the attackers had hardcoded a list of MAC addresses in the trojanized samples and this list was used to identify the actual intended targets of this massive operation. We were able to extract more than 600 unique MAC addresses from over 200 samples used in this attack. Of course, there might be other samples out there with different MAC addresses in their list.
Executive Summary
Operation ShadowHammer is a sophisticated cyber threat actor conducting supply chain attacks targeting users via ASUS Live Update software. The operation leverages hardcoded MAC addresses to precisely target specific individuals or organizations, indicating a high level of technical expertise and strategic focus.
Goals & Targeting
Operation ShadowHammer's strategic objectives appear focused on disrupting specific targets within the technology sector. The targeting of users through hardcoded MAC addresses suggests an intention to cause maximum disruption with minimal exposure, possibly aiming for espionage or infrastructure sabotage. The choice of ASUS as a vector indicates an interest in high-profile victims who rely on their software updates, making the operation both precise and potentially damaging.
Enhanced Description
Operation ShadowHammer represents a significant advancement in cyber attack tactics by compromising trusted supply chain infrastructure. The attackers targeted users by infecting legitimate ASUS Live Update files, demonstrating a capability to infiltrate and manipulate software distribution channels. This operation highlights the increasing trend of attacks targeting specific sectors and geographies through highly customized methods. The exploit involved embedding malicious code within update packages, which were then used to target systems based on unique MAC addresses extracted from compromised samples. This approach allowed the attackers to maintain a low profile while maximizing the impact of their campaign.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Campaigns & Victims
Operation ShadowHammer's campaign patterns include a focus on targeted precision rather than broad dissemination. The attackers likely compiled a list of MAC addresses over time, possibly through prior network reconnaissance or compromised systems. Known campaigns suggest a slow operational tempo with patient targeting to maximize effectiveness. Notable operations include the compromise of ASUS Live Update files and distribution via legitimate update servers.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the operational nature of Operation ShadowHammer due to concrete evidence of supply chain compromise. Areas with potential gaps include exact attack timelines, full scope of targets beyond identified MAC addresses, and precise motivations behind the operation.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
10
IOCs
0
Observed Data
0
Tactics