Hundreds of thousands of consumers of the Taiwan-based electronics giant ASUS received the malware through the company's dependable automatic software update programme after an attacker took over the company's server and used it to distribute it to devices.
TPRM report: https://scoringcyber.rankiteo.com/company/asus
"id": "asu15138323",
"linkid": "asus",
"type": "Malware",
"date": "03/2017",
"severity": "75",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'customers_affected': 'Hundreds of thousands',
'industry': 'Electronics',
'location': 'Taiwan',
'name': 'ASUS',
'size': 'Large',
'type': 'Corporation'}],
'attack_vector': 'Supply Chain Attack',
'description': 'Hundreds of thousands of consumers of the Taiwan-based '
'electronics giant ASUS received the malware through the '
"company's dependable automatic software update programme "
"after an attacker took over the company's server and used it "
'to distribute it to devices.',
'impact': {'systems_affected': 'Hundreds of thousands of devices'},
'initial_access_broker': {'entry_point': 'Compromised Update Server'},
'title': 'ASUS Software Update Malware Distribution',
'type': 'Malware Distribution',
'vulnerability_exploited': 'Compromised Update Server'}