GEEKOM Driver Malware Contacts Domain Previously Associated With Asruex C2

GEEKOM has confirmed that a driver package flagged as malicious was hosted on an outdated support page for its mini PCs.

The company said the file remained online after its newer support system replaced the old resource, allowing users to find and download it through search-engine results.

The incident raised concern because driver packages are normally trusted software components. Users often download them to fix Wi-Fi, Ethernet, audio, graphics, or chipset problems.

A malicious or compromised driver installer can therefore pose a serious supply-chain risk, as victims may run it believing it came from the device manufacturer.

Reports identified the affected file as a LAN driver package. GEEKOM said the problematic installer was hosted on its own support infrastructure, although the old page was not linked from the company’s regular website navigation.

The vendor has not explained how the malware reached its servers. The headline references network communication with a domain previously associated with Asruex command-and-control infrastructure.

However, GEEKOM’s public statement, as reproduced by VideoCardz, does not confirm an Asruex attribution, identify the specific contacted domain, or provide technical indicators such as file hashes, IP addresses, or traffic logs.

That connection should therefore be treated as a reported indicator requiring independent validation rather than a confirmed attribution.

GEEKOM Contacts Asruex C2

GEEKOM said its review found the issue was limited to legacy support pages. It stated that current driver download pages showed no similar anomalies and that the affected package was not included in the Windows installation shipped with its mini PCs. This means owning a GEEKOM device alone does not indicate compromise.

The company has apologized and said it is removing the affected legacy files and pages. It also plans to strengthen resource-management and review processes to reduce the risk of outdated or unverified files remaining available online.

The case highlights a recurring security problem: old web resources can remain accessible long after a company migrates to a new portal. Even if such pages are removed from menus, search engines may continue to index them.

Attackers can exploit this gap by targeting abandoned download locations, compromised storage, or poorly monitored content repositories.

Organizations should maintain complete inventories of public-facing assets, including archived support pages, download servers, cloud storage buckets, and redirect endpoints.

Files offered for download should be regularly scanned, cryptographically signed where possible, and verified against known-good hashes. Old pages should be removed or redirected quickly.

GEEKOM advised users who downloaded the affected LAN driver package not to run it and to delete any local copy.

Users who may have executed the file should perform a full scan using Microsoft Defender or another trusted security product, videocardz said.

For replacement drivers, GEEKOM recommends Windows Update, the official Realtek website, or its updated support portal.

The company also suggested a clean Windows installation using Microsoft’s official installation image for users seeking additional assurance.

Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN. Gain complete phishing visibility to strengthen your SOC and reduce MTTR   

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories