Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Operation ShadowHammer

Operation ShadowHammer

TLP:CLEAR
Active

Description

Newly discovered supply chain attack that leveraged ASUS Live Update software. The goal of the attack was to surgically target an unknown pool of users, which were identified by their network adapters’ MAC addresses. To achieve this, the attackers had hardcoded a list of MAC addresses in the trojanized samples and this list was used to identify the actual intended targets of this massive operation. We were able to extract more than 600 unique MAC addresses from over 200 samples used in this attack. Of course, there might be other samples out there with different MAC addresses in their list.

AI Analysis

· 2 weeks ago

Executive Summary

Operation ShadowHammer is a sophisticated cyber threat actor conducting supply chain attacks targeting users via ASUS Live Update software. The operation leverages hardcoded MAC addresses to precisely target specific individuals or organizations, indicating a high level of technical expertise and strategic focus.

Goals & Targeting

Operation ShadowHammer's strategic objectives appear focused on disrupting specific targets within the technology sector. The targeting of users through hardcoded MAC addresses suggests an intention to cause maximum disruption with minimal exposure, possibly aiming for espionage or infrastructure sabotage. The choice of ASUS as a vector indicates an interest in high-profile victims who rely on their software updates, making the operation both precise and potentially damaging.

Enhanced Description

Operation ShadowHammer represents a significant advancement in cyber attack tactics by compromising trusted supply chain infrastructure. The attackers targeted users by infecting legitimate ASUS Live Update files, demonstrating a capability to infiltrate and manipulate software distribution channels. This operation highlights the increasing trend of attacks targeting specific sectors and geographies through highly customized methods. The exploit involved embedding malicious code within update packages, which were then used to target systems based on unique MAC addresses extracted from compromised samples. This approach allowed the attackers to maintain a low profile while maximizing the impact of their campaign.

Key Capabilities

  • Supply chain compromise
  • Precision targeting via MAC filtering
  • Use of legitimate update channels
  • Custom malware distribution

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Discovery
Lateral Movement

ATT&CK Techniques

T1594
T1053.002

Campaigns & Victims

Operation ShadowHammer's campaign patterns include a focus on targeted precision rather than broad dissemination. The attackers likely compiled a list of MAC addresses over time, possibly through prior network reconnaissance or compromised systems. Known campaigns suggest a slow operational tempo with patient targeting to maximize effectiveness. Notable operations include the compromise of ASUS Live Update files and distribution via legitimate update servers.

IOC Patterns

  • Presence of specific hash values in file downloads
  • Network connections to asushotfix.com or related domains
  • Unusual activity in ASUS update processes
  • Execution of rundll32.exe with unexpected parameters

Recommended Actions

  • Validate software updates through multiple independent sources before deployment.
  • Implement endpoint detection solutions to monitor for suspicious script executions.
  • Monitor network traffic for connections to known malicious IPs and domains associated with ShadowHammer.

Suggested Tags

APT
Supply Chain Attack
MAC Address Targeting

Confidence Assessment

High confidence in the operational nature of Operation ShadowHammer due to concrete evidence of supply chain compromise. Areas with potential gaps include exact attack timelines, full scope of targets beyond identified MAC addresses, and precise motivations behind the operation.

Intel Summary

0

Techniques

0

Tools

1

Campaigns

10

IOCs

0

Observed Data

0

Tactics

Tags

Supply Chain Attack
APT
MAC Address Targeting

Details

Type
Criminal
Confidence
70%
Added
May 6, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.