Geekom has confirmed that a LAN driver available for its AMD mini PC lines contained the Asruex backdoor malware, exposing users to credential theft and remote access attacks. The company removed the malicious package after the discovery was reported by Videocardz.

What You Need to Know

The infected driver installer granted administrator level permissions, allowing attackers to intercept keystrokes, steal passwords and access systems remotely. The malware connected to command and control servers. Geekom has offered guidance and advised a full system wipe. The affected driver was hosted on a legacy support page that remained indexed by search engines.

Affected Mini PC Lines

The compromised LAN driver was available for several Geekom mini PC models. Users who downloaded the driver from the company's support site may have installed the infected file. The affected lines include:

  • A7 and A8: Older AMD based mini PCs in Geekom's lineup
  • AE7 and AE8: Mid range AMD models that rely on the same LAN driver
  • AX7 Pro and AX8 Pro: Higher performance mini PCs also affected by the tainted package

Geekom stated the driver was on a legacy page that had already been replaced and was no longer accessible through normal navigation. However, the page remained indexed by search engines, making it discoverable through Google and other tools.

Discovery and Response

Videocardz identified the malware using multiple detection engines including VirusTotal, FileScan.IO, MetaDefender and Yarafy. The firm asked Videocardz to retract the reporting, a request that was denied. Geekom has since removed the malicious package and issued an apology.

The Asruex backdoor is designed to steal data, intercept keystrokes and retrieve passwords. It connects to command and control centers, giving attackers persistent remote access to infected machines. For users who may have installed the driver, a full system wipe or at least an offline Windows Defender scan is recommended.

Why This Matters

The incident highlights the risks of downloading drivers from manufacturer websites, even from legitimate sources. For Geekom users, the trust placed in official support pages was undermined by a compromised package that could have gone unnoticed for longer. The episode also echoes past security lapses at other hardware makers: AceMagic shipped factory installed spyware in 2022, and Asus faced a poisoned software update incident in 2019 that affected roughly one million systems.

Smaller OEMs like Geekom often manage software with limited resources. The company's reliance on legacy support pages and its initial response to retract reporting suggest a reactive posture rather than proactive security monitoring. Users of mini PCs from any brand should treat driver downloads with caution and prefer Windows Update when possible.