MYBIGGAMING
LIVE
Agothic
Hardware 18 August 2026 2 min read

Geekom Admits Malware in Network Drivers for AMD Mini PCs

Manufacturer Geekom has confirmed that its network driver installers for certain AMD-based mini-PCs contained the Asruex backdoor. The company has removed the files and issued user guidance.
Author: Гика PC
Geekom Admits Malware in Network Drivers for AMD Mini PCs

Geekom has officially acknowledged the presence of malicious software in its network driver packages for a range of AMD-based mini-PCs. Installers for models including the A7, A8, AE7, AE8, AX7 Pro, and AX8 Pro series were found to contain the Asruex backdoor, which granted attackers administrative privileges.

The Incident Explained

According to Videocardz, the LAN driver installers hosted on Geekom's official support page were laced with malware. Upon installation, this software obtained administrator-level permissions, enabling it to steal data, intercept keystrokes, and retrieve passwords.

The malicious code connected to command-and-control centers, allowing remote access to infected machines at any time. It is important to note that the hardware itself was not compromised out-of-the-box; the vulnerability arose solely from downloading and installing drivers directly from the manufacturer's website.

Geekom's Response

Following the investigation by Videocardz, Geekom removed the suspicious package from its archives and issued an official apology. The company stated that the infected file was located on a "legacy page" that had already been replaced and was no longer accessible through standard navigation, though it remained indexed by search engines.

Geekom also requested that Videocardz retract its original reporting, a move that was denied by the independent source. Independent verification confirmed the presence of the Asruex backdoor using four separate detection engines: VirusTotal, FileScan.IO, MetaDefender, and Yarafy.

Recommendations for Users

If you own a Geekom mini-PC from the affected series and previously installed LAN drivers from the official site, experts recommend performing a full system wipe or running an offline scan with Windows Defender. Simply removing one file is insufficient, as the malware may have already accessed critical system resources.

Experts remind users to always obtain driver packages for new installations via Windows Update, visiting manufacturer websites only when necessary. This practice is particularly relevant for smaller OEMs where software quality can sometimes take a backseat to hardware production.

Article author

Гика

Quick actions