Geekom Removes Malware-Laced Network Drivers for AMD Mini PCs
The company scrubbed a legacy support page containing the Asruex backdoor after the threat was reported by Videocardz.
Geekom has admitted that a network driver installer hosted on one of its legacy support pages contained malware. The company has since removed the malicious package and the outdated page while issuing an apology and guidance to affected users.
The security breach affected several AMD-based mini PC models, specifically the A7, A8, AE7, AE8, AX7 Pro, and AX8 Pro. The malicious file was identified as the Asruex backdoor, a threat first reported by Videocardz and subsequently confirmed by Geekom. According to the company, the compromised driver was located on a legacy page that had already been replaced and was no longer accessible through normal support navigation, though it remained indexed by search engines.
The Scope of the Infection
Geekom clarified that the malware was not present in the hardware or the pre-installed operating systems shipped with the devices. The risk was limited exclusively to users who discovered and downloaded the specific driver package from the outdated web page via search engine results. Once the issue was brought to light, Geekom took immediate action to scrub the malicious installer and the associated legacy page from its web presence.
Why It Matters
This incident is particularly concerning because driver installers typically require administrator-level permissions to execute. By granting these privileges, the Asruex backdoor could potentially allow remote attackers to maintain persistent access to an infected PC via command-and-control centers. Such access enables malicious actors to intercept keystrokes, retrieve sensitive passwords, and steal private data from the host system.
The situation underscores a critical vulnerability in how users seek technical support. Many users rely on search engine results to find drivers quickly, which can lead them to outdated or "ghost" pages that are no longer monitored by the manufacturer but remain live on the internet. This creates a significant attack vector if those legacy pages are compromised or contain outdated, insecure software.
What's Next
Users of the affected A-series and AX-series mini PCs are encouraged to follow Geekom's official guidance to ensure their systems are clean. While the company has removed the source of the infection, the incident serves as a warning for the broader industry regarding the management of legacy web assets. Security researchers will likely continue to monitor for other instances of the Asruex backdoor in similar supply-chain or support-channel compromises.