aiexpert
Home / News / Brief
Chips · Aug 17, 2026, 08:04 PM · 2 sources

Geekom admits shipping malware-infected LAN drivers for AMD mini-PCs

Geekom has admitted to shipping malware-laced network drivers for its A7, A8, AE7, AE8, AX7 Pro, and AX8 Pro mini-PCs. The LAN driver installer was infected with Asruex backdoor malware, which grants administrator-level permissions and allows attackers to steal data, intercept keystrokes, retrieve passwords, and establish remote command-and-control access. Videocardz detected the malware using four separate engines: VirusTotal, FileScan.IO, MetaDefender, and Yarafy.

Geekom stated the infected driver was hosted on a legacy support page that had been replaced but remained indexed by search engines—meaning users finding the driver via Google or AI search could unknowingly download the compromised version. The company has removed the package and apologized. Notably, Geekom initially requested Videocardz retract the disclosure, a request Videocardz denied. The company confirmed the machines were not vulnerable out-of-the-box; only users who manually installed the driver from that legacy page were affected.

This incident underscores supply-chain risk in consumer hardware, particularly among smaller ODMs where software security practices can lag behind hardware development. Similar incidents have hit AceMagic (Bladabindi, Redline malware from factory) and ASUS (poisoned 2019 software updates). For architects building on consumer mini-PC infrastructure or integrating edge devices into production systems, the lesson is clear: validate driver sources through Windows Update or direct manufacturer current support pages, never legacy or search-indexed URLs.

Sources

Everything this brief rests on
  1. 01 Primary source tomshardware.com
  2. 02 Tom's Hardware: Geekom admits to shipping malware-laced network drivers for AMD mini PCs tomshardware.com