Operation ShadowHammer ASUS is the last victim of a clamorous supply chain attack that delivered a backdoor to more than one million users, Kaspersky Lab reported. The attack took place between June and November 2018, but experts discovered it in January 2019. Attackers digitally signed their malware with a stolen digital certificate used by the vendor to sign legitimate binaries, a technique already observed in other supply chain attacks such as the CCleaner and ShadowPad hacks. The goal of the attack was to surgically target an unknown pool of users, identified by their network adapters MAC addresses.”]
Source: https://securityaffairs.co/wordpress/82880/hacking/operation-shadowhammer-asus-attack.html

