GEEKOM Mini PC Realtek LAN Driver Package Found Infected With Asruex Trojan

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A network driver download is meant to get a computer online. In this case, it became a potential malware route after a Realtek LAN driver package on a legacy GEEKOM support page was flagged as carrying the Asruex Trojan.

The exposure involved a downloadable installer, not hardware leaving the factory.

That distinction does not remove the risk for people who found the older page through search results, downloaded the package, and ran it with elevated permissions.

VideoCardz analysts noted that the file remained on GEEKOM’s support infrastructure after the newer support system replaced the old page.

The page was no longer linked in normal navigation, yet it could still be reached through search engines, creating a hidden but practical attack path.

GEEKOM said in a report shared with Cyber Security News (CSN) that the incident shows why outdated downloads can become a security liability after a website redesign.

A driver package carries an air of legitimacy, so someone restoring connectivity may be less likely to question a file presented by the device maker’s support portal.

GEEKOM Mini PC Realtek LAN Driver Package Found

GEEKOM confirmed that the affected driver remained on an outdated support resource after its replacement went live.

It said its review of current support pages found no similar issue, and that the pre-installed Windows image on its mini PCs did not include the flagged file.

That narrows the known exposure to people who obtained the older LAN package, rather than all device owners.

However, the company has not said how malware reached its servers, leaving open whether the file was compromised before upload or the hosting environment was changed later.

The file was available in Geekom’s download section (Source – GEEKOM)

The route resembles other malicious driver distribution cases, where ordinary support software gives attackers a persuasive delivery channel.

It also shows why users should treat old search results carefully, even when the destination appears to belong to a familiar vendor.

While GEEKOM is removing the legacy files and pages while tightening review and resource-management procedures. The company also apologised to users.

The company asked VideoCardz to consider removing the original report, but the publication declined because GEEKOM had confirmed the malware-hosting issue.

Public reporting matters because users may have reached an obsolete resource through a saved link, forum post, or search result.

What Downloaded Users Should Do Now

Anyone who saved the affected installer should delete it and should not run it.

People who executed it should run a complete scan with Windows Security or another trusted anti-malware product, then replace the network driver through Windows Update, the official Realtek website, or GEEKOM’s current support page.

GEEKOM also suggested a clean Windows installation from Microsoft’s official image for people seeking added assurance.

That is a cautious option, not evidence that every machine is compromised, but it can be reasonable after a potentially malicious installer was executed with elevated access.

The practical lesson is to use the current support portal reached from the site’s main navigation, not old direct links surfaced by a search.

The danger is part of a broader pattern of trusted update server compromises, in which normal delivery channels make harmful files look routine.

For organisations, this is a reminder to retain downloaded drivers, record their source, and scan software before deployment.

A basic approval process can help stop poisoned software supply chains from reaching many endpoints through a single installer.

It is also important not to confuse ownership with infection. GEEKOM says merely owning one of its mini PCs does not mean a system is affected; the concern is limited to users who downloaded or ran the flagged legacy package.

Users needing support should avoid circulating old installers.

It does demonstrate how quickly trust can shift when a support download is flagged. Current download pages and removal of obsolete files remain key safeguards against fake download site threats.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world