March 26, 2019 By David Bisson 2 min read

Security researchers believe a supply chain attack known as Operation ShadowHammer may have distributed a backdoor to more than 1 million users.

Kaspersky Lab first discovered Operation ShadowHammer back in January 2019. The attackers behind the campaign directed their supply chain attack against the ASUS Live Update software, a utility that comes preinstalled on most computers built by ASUS. The software automatically receives updates for certain components, such as the Basic Input/Output System (BIOS), Unified Extensible Firmware Interface (UEFI) and other applications.

Kaspersky Lab observed 57,000 users of its security products who had installed the backdoor on their machines. The security firm can’t calculate the total number of users affected by the attack from just its own data, but it estimated that the campaign could have affected at least 1 million users. Even so, Kaspersky Lab found in its analysis that the likely goal of Operation ShadowHammer was to target an unknown pool of users via their network adapters’ media access control (MAC) addresses.

The Dangers of a Supply Chain Attack

Operation ShadowHammer isn’t the only sophisticated supply chain attack that’s emerged in the past few years. In September 2017, researchers at Morphisec reported that threat actors had succeeded in covertly modifying the Avast-owned security application CCleaner with a backdoor. This attack subsequently linked as many as 2.27 million users to a server under the attackers’ control.

A few months prior, wiper malware known as Nyetya/NotPetya affected many organizations and multinational corporations operating in Ukraine. Researchers at Cisco Talos launched an investigation into some of the key aspects of this outbreak and discovered that malefactors had conducted a supply chain attack against MeDoc, the makers of a Ukranian accounting software package, to produce a malicious update disguised as ransomware and serve this payload to the software’s users.

Blocking Attacks Like Operation ShadowHammer

Security professionals can help defend against campaigns similar to Operation ShadowHammer by continuously monitoring their third-party connections. In doing so, security personnel should use firewall rules and other common methods to stay on the lookout for inbound connections.

Organizations should also invest in an artificial intelligence-based detection solution that can analyze networks for suspicious behaviors that a human eye might miss and protect the organization against sneaky digital threats like zero-day malware.

More from

When ransomware kills: Attacks on healthcare facilities

4 min read - As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients’ lives are literally on the line.Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during…

AI and cloud vulnerabilities aren’t the only threats facing CISOs today

6 min read - With cloud infrastructure and, more recently, artificial intelligence (AI) systems becoming prime targets for attackers, security leaders are laser-focused on defending these high-profile areas. They’re right to do so, too, as cyber criminals turn to new and emerging technologies to launch and scale ever more sophisticated attacks.However, this heightened attention to emerging threats makes it easy to overlook traditional attack vectors, such as human-driven social engineering and vulnerabilities in physical security.As adversaries exploit an ever-wider range of potential entry points…

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today