Threat reportSupply ChainTL-2026-2059
GEEKOM Mini PC Legacy Support Page Distributed Trojanized Realtek LAN Driver Infected with Asruex
GEEKOM Mini PC Legacy Support Page Distributed Trojanized (TL-2026-2059) is a medium-severity supply-chain compromise, first published 2026-08-18. It has no confirmed attribution, affects GEEKOM Realtek LAN/PCIe driver package for A7, A8, AE7, AE8, AX7 Pro, maps to 14 MITRE ATT&CK techniques (T1027.002, T1036.001, T1055.001), and is covered by 9 detection rules and 16 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 14MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 16Indicators of compromise
Key facts for TL-2026-2059
- Threat ID
- TL-2026-2059
- Severity
- MEDIUM
- Status
- PATCHED
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- consumerelectronicsusers, smallbusiness, homeofficeit
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in GEEKOM Mini PC Legacy Support Page Distributed Trojanized
Malware and tooling: Asruex, Malware.Agentb, Win.Trojan.Asruex, FileScan.IO, MetaDefender, VirusTotal, YARAify
How GEEKOM Mini PC Legacy Support Page Distributed Trojanized works
A Realtek LAN/PCIe driver installer (Install_PCIE_Win11_11.10.0720.2022_11222022.exe, SHA-256 1e806ce2fe77671b20c433f6f2088604d7e6addb6dbbb707e7f8bd86c7f573fb) hosted on GEEKOM's deindexed-but-search-discoverable legacy support pages for six AMD-based mini PC models was found infected with the Asruex file-infecting backdoor, with detections traceable to at least December 2024. GEEKOM confirmed pre-installed Windows images were unaffected, removed the legacy files, and apologized on 2026-08-18.
On 2026-08-15, VideoCardz analysts independently downloaded a Realtek PCIe/LAN driver installer directly from GEEKOM's official driver archive for the A7, A8, AE7, AE8, AX7 Pro, and AX8 Pro mini PC series and found that the file, Install_PCIE_Win11_11.10.0720.2022_11222022.exe (SHA-256 1e806ce2fe77671b20c433f6f2088604d7e6addb6dbbb707e7f8bd86c7f573fb, packaged inside Install_PCIE_Win11_11.10.0720.2022_11222022.zip under a 3_LAN directory), was flagged by multiple engines on VirusTotal, FileScan.IO, MetaDefender, and YARAify as ClamAV Win.Trojan.Asruex and the generic ClamAV Malware.Agentb signature. YARAify's database first catalogued the sample on 2025-02-09, and independent outlets (BornCity, blogspan.net) traced the file's presence in GEEKOM's official driver archive back to December 2024 — meaning the infected installer was live and downloadable for roughly 18 months before public disclosure. A forum user (michael73k, cited by igor'sLAB) additionally noted the flagged installer is 5,282 KB, versus a clean 5,021 KB copy of the same-named file previously scanned on VirusTotal two years earlier — a size delta consistent with the file having been substituted or infected sometime after its original 2022-11-22 build/signing date.
The file carries a Realtek Semiconductor Corp. code-signing certificate issued via DigiCert, but signature-verification tooling reports a checksum MISMATCH between the value embedded in the Authenticode signature and the file's actual contents — evidence the binary was modified after Realtek originally signed it. This is consistent with Asruex's documented behavior as a PE (portable executable) infector: Trend Micro's research on the Asruex family (mirrored by SecurityAffairs and malware.news after the primary Trend Micro page returned HTTP 403 on refetch) describes it compressing and encrypting an original host executable and appending it as a new PE section (historically named .EBSS/.__EBSS), so the trojanized binary drops its backdoor payload with a randomly-assigned filename while still transparently executing the original host program — which both explains the broken signature and would make superficial inspection of installer behavior look normal to an end user. The same Trend Micro research documents the broader Asruex family's full infection chain, which the GEEKOM sample's family-level detections (Win.Trojan.Asruex, Malware.Agentb) place this installer within: initial infection historically begins via a malicious shortcut (.lnk) file containing a PowerShell download script that also propagates by tainting files reachable on removable and network drives; the dropped infector performs extensive anti-analysis checks (anti-debugging strings such as "avast! Sandbox\WINDOWS\system32\kernel32.dll", and sandbox/VM detection via computer names, usernames, module exports, filenames, running processes, process versions, and disk name strings) before installing itself, at times via DLL injection into legitimate Windows processes and by dropping itself proxied through the signed system binary rundll32.exe; a document-infecting variant of the same family additionally weaponizes two long-patched vulnerabilities — CVE-2012-0158 (an ActiveX buffer-overflow RCE in MS Office 2003/2007/2010 affecting Word documents) and CVE-2010-2883 (a stack-based buffer overflow in Adobe Reader/Acrobat 8.x–9.x CoolType.dll) — to inject shellcode into Word and PDF files respectively while the decoy document displays normally. None of the GEEKOM-incident-specific reporting confirms which of these family capabilities were live in the specific driver-installer sample beyond the PE-infector/broken-signature behavior; the document-exploitation and LNK/PowerShell-downloader techniques are documented general capabilities of the Asruex malware family the sample was multi-engine-classified as, not independently observed in this driver-installer distribution vector. Asruex has circulated since at least 2015 and is most commonly associated with the DarkHotel actor cluster (aka APT-C-06/DUBNIUM), though none of the GEEKOM-incident reporting attributes this specific distribution event to any named intrusion set — the malware-family classification came from signature detection, not confirmed campaign attribution.
Exposure was limited by two factors documented by GEEKOM: the page was a legacy resource no longer linked from the current Support navigation (superseded when GEEKOM migrated to a newer support system) but remained reachable via search-engine indexing, and pre-installed Windows images on GEEKOM mini PCs did not include the flagged file — only users who manually located the legacy page and downloaded/ran the installer with the elevated permissions a driver install requires were at risk. GEEKOM confirmed via internal review that current support pages show no similar issue, removed the legacy files and pages, apologized to affected users on 2026-08-18, and advised anyone who downloaded the installer to delete it without running it, and anyone who already ran it to scan with Windows Security or another trusted anti-malware tool, replace drivers via Windows Update or Realtek's official site, or perform a clean Windows reinstall if compromise is suspected.
MITRE ATT&CK techniques used in TL-2026-2059
Defense Evasion
T1027.002 Software Packing; T1036.001 Invalid Code Signature; T1055.001 Dynamic-link Library Injection; T1140 Deobfuscate/Decode Files or Information; T1218.011 Rundll32; T1497.001 System Checks
Execution
T1059.001 PowerShell; T1203 Exploitation for Client Execution; T1204.002 Malicious File
Command and Control
T1071 Application Layer Protocol
Lateral Movement
Initial Access
T1091 Replication Through Removable Media; T1195.002 Compromise Software Supply Chain
Persistence
Affected products and versions in GEEKOM Mini PC Legacy Support Page Distributed Trojanized
- GEEKOM — Realtek LAN/PCIe driver package for A7, A8, AE7, AE8, AX7 Pro, and AX8 Pro AMD-based mini PCs
Vulnerable versions: Install_PCIE_Win11_11.10.0720.2022_11222022 (embedded build date 2022-11-22), hosted on GEEKOM's legacy support pages and in circulation since at least December 2024
Fixed in: Driver obtained directly from Realtek's official site or via Windows Update; GEEKOM's current support pages verified clean as of 2026-08-18; Pre-installed Windows images on GEEKOM mini PCs were never affected
Remediation for GEEKOM Mini PC Legacy Support Page Distributed Trojanized
Patches
- GEEKOM removed the affected legacy support files and pages and confirmed current support resources are clean as of 2026-08-18
Immediate actions
- Delete any locally saved copies of Install_PCIE_Win11_11.10.0720.2022_11222022.exe or the Install_PCIE_Win11_11.10.0720.2022_11222022.zip archive without executing them
- If the installer was already executed, run a full scan with Windows Security (Defender) or another trusted anti-malware/EDR tool on the affected system
Workarounds
- For systems where compromise is suspected or confirmed, perform a clean Windows reinstallation and reinstall drivers only from GEEKOM's current support page or Realtek's official site
Longer-term hardening
- Source LAN/network drivers directly from the component manufacturer (Realtek) or via Windows Update rather than OEM-bundled driver archives on vendor support pages
- Verify Authenticode signature integrity (not just certificate presence) on downloaded driver installers before execution; a checksum MISMATCH indicates post-signing tampering even when a valid-looking vendor certificate is attached
- Treat unexpected file-size deltas on a redistributed vendor binary (e.g. this installer's 5,282 KB vs a prior-known-clean 5,021 KB) as a tampering indicator worth an independent hash check
Weaknesses (CWE) in GEEKOM Mini PC Legacy Support Page Distributed Trojanized
Timeline of GEEKOM Mini PC Legacy Support Page Distributed Trojanized
- Independent reporting (BornCity, blogspan.net) traces the trojanized Install_PCIE_Win11_11.10.0720.2022_11222022.exe hash to GEEKOM's official driver archive since at least December 2024.
- The file's SHA-256 hash is first documented in the abuse.ch YARAify database, matching ClamAV Win.Trojan.Asruex and Malware.Agentb signatures.
- VideoCardz publishes the first report identifying the flagged file in GEEKOM's driver archive for the A7, A8, AE7, AE8, AX7 Pro, and AX8 Pro mini PC series; igor'sLAB independently confirms the finding and reports a forum user's discovery that the flagged 5,282 KB installer differs in size from a clean 5,021 KB copy of the same filename scanned on VirusTotal roughly two years earlier.
- VideoCardz analysts independently download the driver installer directly from GEEKOM's official support archive and verify the malware flags across VirusTotal, FileScan.IO, MetaDefender, and YARAify.
- Cyber Security News, Tom's Hardware, Notebookcheck, igor'sLAB, BornCity, and blogspan.net publish coverage of the incident and GEEKOM's response.
- GEEKOM removes the affected legacy files and pages, tightens its support-content review procedures, and advises affected users to delete/not-run the installer, scan with anti-malware tools, and source drivers from official channels going forward.
- GEEKOM publicly apologizes, confirms the flagged installer was an outdated file on a deindexed legacy support page, confirms pre-installed Windows images were unaffected, and confirms current support pages are clean.
Sources cited for GEEKOM Mini PC Legacy Support Page Distributed Trojanized
- GEEKOM Mini PC Realtek LAN Driver Infection (Asruex Trojan)
- GEEKOM Mini PC driver archive contains file flagged as malware (update)
- GEEKOM apologizes for hosting malware in driver package for its Mini PCs
- Geekom admits to shipping malware-laced network drivers for AMD mini PCs
- GEEKOM: Suspicious LAN driver file in AMD mini PCs
- Official mini PC driver package from Geekom triggers malware alert
- GEEKOM Mini-PCs: Malware in offiziellen Treiberpaketen seit Dezember
- Geekom: Treiberpaket mit gebrochener Realtek-Signatur
- Asruex Backdoor Variant Infects Word Documents and PDFs Through Old MS Office and Adobe Vulnerabilities
- Trojan:Win32/Asruex.A threat description
- A new variant of Asruex Trojan exploits very old Office, Adobe flaws
- Asruex Backdoor Variant Infects Word Documents and PDFs (mirror)
Detection coverage for TL-2026-2059
As of 2026-08-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2059 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.