Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
WordPress Sites Hijacked for StopAndProtect Malware C2 Servers
August 18, 2026
Critical MLflow SSRF vulnerability CVE-2023-XXXX exploited in the wild
August 18, 2026
French Tax Authority Data Breach Exposes Over 600,000 Users’ Personal Tax Data
August 18, 2026
Home/Threats/GEEKOM Mini PC Realtek LAN Driver Infected With Asruex Trojan
Threats

GEEKOM Mini PC Realtek LAN Driver Infected With Asruex Trojan

Key Takeaways A Realtek LAN driver package on a legacy GEEKOM support page was found to be infected with the Asruex Trojan. The malware was distributed via a downloadable installer, not pre-installed...

Marcus Rodriguez
Marcus Rodriguez
August 18, 2026 4 Min Read
3 0

Key Takeaways

  • A Realtek LAN driver package on a legacy GEEKOM support page was found to be infected with the Asruex Trojan.
  • The malware was distributed via a downloadable installer, not pre-installed hardware.
  • While the page was no longer actively linked, it remained accessible through search engines, creating a hidden attack vector.
  • GEEKOM has apologized and is removing the affected files and pages, emphasizing that only users who downloaded and executed the specific legacy package are at risk.

Compromised GEEKOM Driver Delivers Asruex Trojan

A Realtek LAN driver package, hosted on an outdated GEEKOM support page, has been identified as containing the potent Asruex Trojan. This discovery highlights a critical supply chain vulnerability where an essential network driver, intended to facilitate internet connectivity, instead became a conduit for malware delivery. The incident underscores the persistent risks associated with legacy online resources, even after a vendor’s website redesign.

Table Of Content

  • Key Takeaways
  • Compromised GEEKOM Driver Delivers Asruex Trojan
  • GEEKOM’s Response and Scope of Exposure
  • What You Should Do

The infection originated from a downloadable installer, not from hardware shipped directly from the factory. This distinction is crucial, yet it does not diminish the threat to users who may have located the older support page via search engines, downloaded the compromised package, and subsequently executed it with administrative privileges.

Analysts at VideoCardz observed that despite a new support system being implemented, the malicious file persisted on GEEKOM’s older infrastructure. Although the page was no longer integrated into the website’s primary navigation, its continued accessibility through search results presented a latent but viable pathway for attackers to exploit. GEEKOM said in a report shared with Cyber Security News (CSN) that this incident exemplifies how outdated downloads can evolve into significant security liabilities following website overhauls. The inherent legitimacy of a driver package, especially one offered directly by a device manufacturer, can lead users to bypass typical scrutiny, making them more susceptible to malware infection.

GEEKOM’s Response and Scope of Exposure

GEEKOM has confirmed that the compromised driver package was indeed present on an superseded support resource after its replacement went live. The company stated that a review of its current support pages revealed no similar issues, and importantly, the pre-installed Windows images on its mini PCs do not contain the flagged malware. This limits the known exposure primarily to individuals who actively sought out and downloaded the older LAN driver package, rather than all owners of GEEKOM devices.

However, GEEKOM has not publicly disclosed the mechanism by which the malware infiltrated its servers. This leaves open questions regarding whether the file was compromised prior to its upload or if the hosting environment itself was later breached. This ambiguity is a key concern for cybersecurity professionals, as it impacts the understanding of the attack vector and potential broader implications.

This scenario mirrors other documented cases of malicious driver distribution, where seemingly benign support software is leveraged to create a highly credible delivery channel for malware. It also serves as a stark reminder for users to exercise extreme caution with old search results, even when the destination appears to be an official vendor portal.

GEEKOM is actively engaged in removing the legacy files and pages and is implementing stricter review and resource-management protocols. The company has also issued an apology to its users. VideoCardz reportedly declined GEEKOM’s request to remove its original report, citing the importance of public awareness given the vendor’s confirmation of the malware-hosting issue. Public reporting remains vital because users can access obsolete resources through various means, including saved links, forum discussions, or search engine results.

What You Should Do

  • Delete Affected Files: Immediately delete any downloaded “Realtek LAN driver” package from GEEKOM’s legacy support pages. Do not execute it.
  • Run Full Malware Scans: If you have executed the affected installer, perform a comprehensive scan of your system using Windows Security or a reputable third-party anti-malware solution.
  • Update Network Drivers: Replace your current network driver by using Windows Update, downloading directly from the official Realtek website, or obtaining it from GEEKOM’s current, official support page.
  • Consider a Clean OS Installation: For maximum assurance, GEEKOM suggests a clean installation of Windows using an official Microsoft image, especially if the malicious installer was run with elevated privileges. This is a cautious step but can be prudent to ensure complete removal of potential persistent threats.
  • Exercise Caution with Downloads: Always prioritize downloading drivers and software from a vendor’s current, officially linked support portal, avoiding outdated or search-engine-derived links.
  • Implement Software Review: For organizations, establish a rigorous process for reviewing and scanning all downloaded drivers and software before deployment to prevent compromised software supply chain attacks.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

BTMob Fraud-as-a-Service Platform Uses 1,400 Servers for Android Takeovers

Next Post

JWR Phishing Framework Steals Banking Credentials via WebSocket Control

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
GEEKOM Mini PC Realtek LAN Driver Infected With Asruex Trojan
August 18, 2026
BTMob Fraud-as-a-Service Platform Uses 1,400 Servers for Android Takeovers
August 18, 2026
Critical Vulnerability in Electron Apps Hides Malware
August 18, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us