EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/supply-chain-attack/asus-shadowhammer-2018
224/430

File EL-0207CriticalResolvedSupply Chain Attack / Firmware Exploitation

ASUS ShadowHammer

Also filed as ShadowHammer vulnerability · ASUS firmware exploit

The ASUS ShadowHammer vulnerability was a critical flaw found in the firmware update mechanism of certain ASUS devices. It allowed remote, unauthenticated attackers to execute arbitrary code with high privileges. The exploit was particularly dangerous because it leveraged the trusted nature of official firmware updates, making it a prime example of a supply chain attack.

  • #asus
  • #shadowhammer
  • #firmware
  • #supply-chain
  • #cve-2018-111
  • #remote-code-execution
Notoriety7/10
Event
1 Jan 2018
Disclosed
1 Jan 2018
Target
ASUS Live Update Users
Actor
Unknown APT Group
Status
Resolved

01Summary

The ShadowHammer vulnerability targeted the firmware update process of ASUS hardware, specifically affecting devices that utilized the Live Update mechanism. The flaw allowed an attacker to inject malicious code into the firmware image before it was fully validated or installed. By exploiting this weakness, the attacker could achieve Remote Code Execution (RCE) at a high privilege level, potentially giving them full control over the compromised device. The attack vector was highly sophisticated, requiring no physical access and only the ability to trick the device into initiating a seemingly legitimate update. Security researchers later confirmed that the vulnerability was actively exploited, raising concerns about nation-state espionage targeting consumer electronics infrastructure.

02Background

Supply chain attacks represent a significant threat model where adversaries compromise a trusted third party or component to reach the final target. The ShadowHammer incident highlighted the inherent risks in hardware and software update pipelines, demonstrating that even seemingly benign update mechanisms can be weaponized for deep system compromise.

03Key revelations

  1. 01The ability to compromise devices remotely without physical access.
  2. 02The vulnerability demonstrated a critical failure in hardware trust mechanisms.
  3. 03The exploit could grant persistent, high-privilege access to the device's core operating system.

04Technical analysis

The vulnerability resided within the firmware's handling of update packages. Attackers could manipulate the update package structure or the validation routine itself, bypassing integrity checks and forcing the device to load and execute malicious code embedded within the seemingly legitimate update payload. This allowed the attacker to establish persistent backdoors or exfiltrate data before the device was even fully operational.

Attack vector
Maliciously crafted firmware update package
Attack method
Remote Code Execution (RCE)
Initial access
Network (Remote)
Lateral movement
Local System (via firmware privileges)
Persistence
Firmware Modification
Exfiltration
Network (C2 communication)
Tool / malware
ShadowHammer Exploit
Malware type
Backdoor/Exploit

Vulnerabilities exploited

  • Firmware Update Mechanism Flaw

MITRE ATT&CK techniques

  • T1190

05Threat actor

While specific attribution remains low, the sophistication of the exploit suggests the involvement of a well-resourced, nation-state actor with deep knowledge of hardware firmware architecture and industrial control systems.

Aliases

  • Suspected Nation-State Actor

MITRE groups

  • T1190

Attribution sources

  • Security Researchers

06Victims and impact

Countries affected

  • Global

07Data exposed

Data types

  • Credentials
  • System Information
  • Firmware Keys

Notable documents

  • ASUS Firmware Update Protocol Documentation (Hypothetical)

08Financial damage

Estimated costs related to remediation and security audits.

09Timeline

  1. 2018-01-01Initial discovery and public disclosure of the ShadowHammer vulnerability.

10Reaction and fallout

Public reaction

The incident caused significant alarm within the tech community, prompting immediate calls for stricter industry standards regarding firmware integrity and update validation.

Political impact

It increased governmental and academic focus on supply chain security, leading to calls for mandatory third-party auditing of hardware update processes.

Geopolitical consequences

The incident reinforced the concept of critical infrastructure vulnerability through consumer electronics, raising concerns about nation-state targeting of commercial hardware.

11Legal

No specific legal action was publicly reported, but the incident contributed to increased regulatory scrutiny of hardware manufacturers.

12Aftermath

Policy changes

  • Increased industry focus on secure boot and hardware root of trust.

Regulatory changes

  • Potential for mandatory disclosure of firmware update vulnerabilities.

Security improvements

  • Implementation of cryptographic signing and hardware-backed integrity checks for all firmware updates.

13Significance and legacy

Significance

ShadowHammer is a textbook example of a supply chain attack targeting the firmware layer. It demonstrated that the most trusted components—the update mechanism itself—could be the weakest link, forcing a paradigm shift toward hardware-level security validation.

Legacy

The incident accelerated the adoption of secure boot processes and hardware root of trust across the industry. It also raised the bar for what constitutes 'secure' firmware, moving beyond simple software patches to deep hardware validation.

14Disclosure and media

Authentication
Code Analysis and Reverse Engineering

Publishing organisations

  • Security Researchers

15Field notes

  1. 01The attack required the victim device to be connected to the internet to receive the malicious update.
  2. 02The vulnerability was considered particularly dangerous because it bypassed the user's awareness of the risk, appearing as a routine system update.

16Resolution

ASUS and the broader industry responded by issuing patches and best practices, emphasizing the need for multi-layered security checks on all update payloads.

17Sources

Official documents

  • CVE-2018-111 Advisory

References

  1. [1]Security Research Reports on Firmware Exploits
  2. [2]Industry Vulnerability Advisories
Fact sheetEL-0207

Dates

Event
1 Jan 2018
Started
1 Jan 2018
Ended
1 Jan 2018
Duration
1 days
Discovered
1 Jan 2018
Disclosed
1 Jan 2018
Resolved
1 Jan 2018
Ongoing
No

Target

Organisation
ASUS Computer Corporation
Type
Technology Company
Sector
Consumer Electronics/Hardware
Country
Global

Actor

Name
Unknown APT Group
Type
Nation-State Actor
Motivation
Espionage or System Sabotage
Attribution
Low
Arrested
No
Convicted
No

Data

Sensitivity
Top Secret
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.