CVE-2025-59374 — ASUS Live Update Embedded Malicious Code Vulnerability

CVE-2025-59374

ASUS Live Update — Operation ShadowHammer Supply Chain Backdoor (APT41 / Brass Typhoon)

What is ASUS Live Update?

ASUS Live Update is a software utility pre-installed on ASUS laptops and desktop computers that automatically checks for and installs driver, BIOS, and software updates. It runs as a background service with elevated system privileges and regularly communicates with ASUS update servers over HTTPS. Because it runs with system-level access, a backdoored version can silently install additional malware, exfiltrate data, or establish persistent access without any user interaction. Supply chain attacks against software update mechanisms are particularly dangerous because victims have no reason to distrust updates from their device manufacturer.

Overview

CVE-2025-59374 formally documents the Operation ShadowHammer supply chain compromise, in which the Chinese state-sponsored group APT41 (Brass Typhoon, Wicked Panda, Barium) breached ASUS infrastructure in 2018 and injected a backdoor into legitimately-signed ASUS Live Update binaries. The backdoored builds were distributed to hundreds of thousands of ASUS users through official ASUS update channels. The malicious code contained a hardcoded list of over 600 MAC addresses targeting specific high-value machines; devices not matching the list were left dormant. ASUS Live Update reached end-of-support in December 2025, and CISA assigned this CVE and added it to the KEV catalog to flag that systems still running old versions may harbor compromised software.

Affected Versions

Product Vulnerable Fixed / Action
ASUS Live Update prior to 3.6.8 All versions distributed during the 2018–2019 compromise window Upgrade to 3.6.8+ to remove malicious code
ASUS Live Update 3.6.8 – 3.6.15 Not affected by ShadowHammer Clean builds
ASUS Live Update (all versions) Product is EoL (Dec 4, 2025) Discontinue use entirely

CISA's guidance: do not use ASUS Live Update in any version. Remove it from all systems.

Technical Details

The vulnerability (CWE-506: Embedded Malicious Code) was introduced via a supply chain compromise. APT41 gained unauthorized access to ASUS's software build or distribution infrastructure and injected a backdoor into ASUS Live Update binaries. The malicious builds were signed with a valid, legitimate ASUS digital certificate — making them cryptographically indistinguishable from authentic updates. Windows's code signing verification would pass for these binaries.

The backdoor logic checked the MAC address of the host's primary network adapter against an encrypted list of over 600 specific MAC addresses. If the MAC address matched a target, the backdoor made a second-stage network connection to attacker-controlled infrastructure to download and execute additional malware. Machines not on the target list were infected with the backdoored binary but left dormant — a technique designed to minimize forensic detection by limiting active malicious behavior to only pre-selected targets.

Discovery

Kaspersky Lab discovered Operation ShadowHammer in January 2019 and publicly disclosed it on 25 March 2019. ASUS acknowledged the compromise and issued a clean version (3.6.8) the same day.

Exploitation Context

APT41 (Brass Typhoon, Wicked Panda, Barium) — a Chinese state-sponsored threat actor with dual espionage and financial crime mandates — conducted Operation ShadowHammer in 2018, targeting specific high-value individuals with surgical precision. The 600+ MAC addresses suggest pre-identified targets of intelligence interest. Kaspersky estimated that backdoored ASUS Live Update binaries were distributed to over one million devices globally, with only a small fraction actively targeted. CISA assigned CVE-2025-59374 in December 2025 as a retrospective action to formally document this known, confirmed exploitation event and prompt removal of the EoL software from federal networks. The KEV deadline of 7 January 2026 required all FCEB agencies to remove ASUS Live Update.

Remediation

  1. Remove ASUS Live Update from all systems — the software is end-of-life and CISA's guidance is to discontinue use entirely. Uninstall via Windows Settings → Apps or use a managed removal script.
  2. For systems running pre-3.6.8 versions: these systems may have been compromised in 2018–2019. Consider them potentially compromised and conduct forensic investigation if these are high-value assets.
  3. Use Kaspersky's ShadowHammer checker tool (available at securelist.com) to verify whether a system's MAC address appears in the list of targeted addresses.
  4. Replace ASUS Live Update's function with enterprise driver/BIOS management tooling (e.g., vendor-specific management tools, SCCM/Intune driver management, BIOS update policies via MDM).
  5. Remove from enterprise asset inventory — if deploying ASUS hardware, ensure new systems' Live Update is uninstalled as part of the standard OS deployment process.

Key Details

PropertyValue
CVE ID CVE-2025-59374
Vendor / Product ASUS — Live Update
NVD Published2025-12-17
NVD Last Modified2025-12-18
CVSS 3.1 Score9.8
CVSS 3.1 VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SeverityCRITICAL
CWE CWE-506 find similar ↗
CISA KEV Added2025-12-17
CISA KEV Deadline2026-01-07
Known Ransomware Use No

CVSS 3.1 Breakdown

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Required Action

CISA BOD 22-01 Deadline: 2026-01-07. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Timeline

DateEvent
2018-06-01APT41 conducts supply chain compromise of ASUS Live Update servers; backdoored binaries distributed to users
2019-01-01Kaspersky Lab discovers Operation ShadowHammer
2019-03-25Kaspersky publicly discloses Operation ShadowHammer; ASUS acknowledges and issues clean version 3.6.8
2025-12-04ASUS Live Update reaches end-of-support (final version 3.6.15)
2025-12-17CVE-2025-59374 assigned (retrospective); CISA adds to KEV catalog; ASUS guidance: discontinue use
2026-01-07CISA BOD 22-01 remediation deadline — FCEB agencies must remove ASUS Live Update