# GEEKOM Mini PC Legacy Support Page Distributed Trojanized Realtek LAN Driver Infected with Asruex

> A Realtek LAN/PCIe driver installer (Install_PCIE_Win11_11.10.0720.2022_11222022.exe, SHA-256 1e806ce2fe77671b20c433f6f2088604d7e6addb6dbbb707e7f8bd86c7f573fb) hosted on GEEKOM's deindexed-but-search-discoverable legacy support pages for six AMD-based mini PC models was found infected with the Asruex file-infecting backdoor, with detections traceable to at least December 2024. GEEKOM confirmed pre-installed Windows images were unaffected, removed the legacy files, and apologized on 2026-08-18.

- **Published:** 2026-08-18T00:00:00Z
- **Last reviewed:** 2026-08-18T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2059
- **ID:** TL-2026-2059
- **Severity:** MEDIUM
- **Category:** SUPPLY_CHAIN
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-08-15, VideoCardz analysts independently downloaded a Realtek PCIe/LAN driver installer directly from GEEKOM's official driver archive for the A7, A8, AE7, AE8, AX7 Pro, and AX8 Pro mini PC series and found that the file, Install_PCIE_Win11_11.10.0720.2022_11222022.exe (SHA-256 1e806ce2fe77671b20c433f6f2088604d7e6addb6dbbb707e7f8bd86c7f573fb, packaged inside Install_PCIE_Win11_11.10.0720.2022_11222022.zip under a 3_LAN directory), was flagged by multiple engines on VirusTotal, FileScan.IO, MetaDefender, and YARAify as ClamAV Win.Trojan.Asruex and the generic ClamAV Malware.Agentb signature. YARAify's database first catalogued the sample on 2025-02-09, and independent outlets (BornCity, blogspan.net) traced the file's presence in GEEKOM's official driver archive back to December 2024 — meaning the infected installer was live and downloadable for roughly 18 months before public disclosure. A forum user (michael73k, cited by igor'sLAB) additionally noted the flagged installer is 5,282 KB, versus a clean 5,021 KB copy of the same-named file previously scanned on VirusTotal two years earlier — a size delta consistent with the file having been substituted or infected sometime after its original 2022-11-22 build/signing date.

The file carries a Realtek Semiconductor Corp. code-signing certificate issued via DigiCert, but signature-verification tooling reports a checksum MISMATCH between the value embedded in the Authenticode signature and the file's actual contents — evidence the binary was modified after Realtek originally signed it. This is consistent with Asruex's documented behavior as a PE (portable executable) infector: Trend Micro's research on the Asruex family (mirrored by SecurityAffairs and malware.news after the primary Trend Micro page returned HTTP 403 on refetch) describes it compressing and encrypting an original host executable and appending it as a new PE section (historically named .EBSS/.__EBSS), so the trojanized binary drops its backdoor payload with a randomly-assigned filename while still transparently executing the original host program — which both explains the broken signature and would make superficial inspection of installer behavior look normal to an end user. The same Trend Micro research documents the broader Asruex family's full infection chain, which the GEEKOM sample's family-level detections (Win.Trojan.Asruex, Malware.Agentb) place this installer within: initial infection historically begins via a malicious shortcut (.lnk) file containing a PowerShell download script that also propagates by tainting files reachable on removable and network drives; the dropped infector performs extensive anti-analysis checks (anti-debugging strings such as "avast! Sandbox\WINDOWS\system32\kernel32.dll", and sandbox/VM detection via computer names, usernames, module exports, filenames, running processes, process versions, and disk name strings) before installing itself, at times via DLL injection into legitimate Windows processes and by dropping itself proxied through the signed system binary rundll32.exe; a document-infecting variant of the same family additionally weaponizes two long-patched vulnerabilities — CVE-2012-0158 (an ActiveX buffer-overflow RCE in MS Office 2003/2007/2010 affecting Word documents) and CVE-2010-2883 (a stack-based buffer overflow in Adobe Reader/Acrobat 8.x–9.x CoolType.dll) — to inject shellcode into Word and PDF files respectively while the decoy document displays normally. None of the GEEKOM-incident-specific reporting confirms which of these family capabilities were live in the specific driver-installer sample beyond the PE-infector/broken-signature behavior; the document-exploitation and LNK/PowerShell-downloader techniques are documented general capabilities of the Asruex malware family the sample was multi-engine-classified as, not independently observed in this driver-installer distribution vector. Asruex has circulated since at least 2015 and is most commonly associated with the DarkHotel actor cluster (aka APT-C-06/DUBNIUM), though none of the GEEKOM-incident reporting attributes this specific distribution event to any named intrusion set — the malware-family classification came from signature detection, not confirmed campaign attribution.

Exposure was limited by two factors documented by GEEKOM: the page was a legacy resource no longer linked from the current Support navigation (superseded when GEEKOM migrated to a newer support system) but remained reachable via search-engine indexing, and pre-installed Windows images on GEEKOM mini PCs did not include the flagged file — only users who manually located the legacy page and downloaded/ran the installer with the elevated permissions a driver install requires were at risk. GEEKOM confirmed via internal review that current support pages show no similar issue, removed the legacy files and pages, apologized to affected users on 2026-08-18, and advised anyone who downloaded the installer to delete it without running it, and anyone who already ran it to scan with Windows Security or another trusted anti-malware tool, replace drivers via Windows Update or Realtek's official site, or perform a clean Windows reinstall if compromise is suspected.

## MITRE ATT&CK

- T1195.002 Compromise Software Supply Chain
- T1091 Replication Through Removable Media
- T1204.002 Malicious File
- T1059.001 PowerShell
- T1203 Exploitation for Client Execution
- T1554 Compromise Host Software Binary
- T1036.001 Invalid Code Signature
- T1027.002 Software Packing
- T1140 Deobfuscate/Decode Files or Information
- T1055.001 Dynamic-link Library Injection
- T1218.011 Rundll32
- T1497.001 System Checks
- T1080 Taint Shared Content
- T1071 Application Layer Protocol

## Sources

- [GEEKOM Mini PC Realtek LAN Driver Infection (Asruex Trojan)](https://cybersecuritynews.com/geekom-mini-pc/)
- [GEEKOM Mini PC driver archive contains file flagged as malware (update)](https://videocardz.com/newz/geekom-mini-pc-driver-archive-contains-file-flagged-as-malware)
- [GEEKOM apologizes for hosting malware in driver package for its Mini PCs](https://videocardz.com/newz/geekom-apologizes-for-hosting-malware-in-driver-package-for-its-mini-pcs)
- [Geekom admits to shipping malware-laced network drivers for AMD mini PCs](https://www.tomshardware.com/tech-industry/cyber-security/geekom-admits-to-shipping-malware-laced-network-drivers-for-amd-mini-pcs-company-responds-with-guidance-removes-malicious-package)
- [GEEKOM: Suspicious LAN driver file in AMD mini PCs](https://www.igorslab.de/en/geekom-driver-package-triggers-malware-scanners-several-amd-mini-pcs-affected/)
- [Official mini PC driver package from Geekom triggers malware alert](https://www.notebookcheck.net/Official-mini-PC-driver-package-from-Geekom-triggers-malware-alert.1369401.0.html)
- [GEEKOM Mini-PCs: Malware in offiziellen Treiberpaketen seit Dezember](https://borncity.com/news/geekom-mini-pcs-malware-in-offiziellen-treiberpaketen-seit-dezember/)
- [Geekom: Treiberpaket mit gebrochener Realtek-Signatur](https://www.blogspan.net/geekom-treiberpaket-realtek-signatur-gebrochen/)
- [Asruex Backdoor Variant Infects Word Documents and PDFs Through Old MS Office and Adobe Vulnerabilities](https://www.trendmicro.com/en_us/research/19/h/asruex-backdoor-variant-infects-word-documents-and-pdfs-through-old-ms-office-and-adobe-vulnerabilities.html)
- [Trojan:Win32/Asruex.A threat description](https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan%3AWin32%2FAsruex.A&ThreatID=2147742113)
- [A new variant of Asruex Trojan exploits very old Office, Adobe flaws](https://securityaffairs.com/90275/malware/asruex-trojan-old-flaws.html)
- [Asruex Backdoor Variant Infects Word Documents and PDFs (mirror)](https://malware.news/t/asruex-backdoor-variant-infects-word-documents-and-pdfs-through-old-ms-office-and-adobe-vulnerabilities/32380)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2059
