Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

From a 7 KB file to a 13-year backdoor operation

A Chinese APT group, Velvet Ant, used a tiny 7 KB malicious file to backdoor a U.S. organization's network in 2008, remaining undetected for 13 years until 2021 by hiding on a major vendor's network devices.

Background

Dubbed "Operation ShadowHammer," this marks the first known supply-chain attack against the ASUS brand. Threat actors known as the "ShadowHammer Group" compromised the legitimate ASUS Live Update Utility by adding a valid digital signature. A relatively small, 7 KB trojanized component was distributed via official support servers to a targeted subset of hundreds of thousands of ASUS users. The malware (called "Bureaubot" or "ASUS ShadowHammer") maintained command-and-control (C2) infrastructure for over a decade. The attack was publicly disclosed and linked to the TA429 group (also associated with the SolarWinds SUNBURST campaign) by Kaspersky in 2019, though attribution remains debated.