GEEKOM Mini PC Driver Package Infected With Asruex Trojan
A legacy driver download on GEEKOM's support site was found to host the Asruex Trojan, posing a risk to users who downloaded and executed it.

A legacy Realtek LAN driver package hosted on an outdated GEEKOM support page was discovered to contain the Asruex Trojan, presenting a significant security risk to unsuspecting users. The compromised installer was accessible via search engine results, creating a hidden attack vector for threat actors. While the affected driver was not part of the hardware's factory image, users who found the legacy page, downloaded the package, and executed it with elevated permissions could have inadvertently infected their systems.
Analysts noted that the malicious file remained on GEEKOM's support infrastructure even after a newer support system replaced the old page. Although the legacy page was no longer linked in the site's primary navigation, its continued presence in search engine indexes made it discoverable. This situation highlights how outdated online resources can become security liabilities, especially when they retain an air of legitimacy, such as driver packages provided by a hardware vendor.
GEEKOM confirmed the incident, stating that the affected driver was on an outdated resource. The company's review of current support pages found no similar issues, and importantly, the pre-installed Windows image on their mini PCs did not contain the flagged file. This narrows the scope of the known exposure to individuals who specifically downloaded and ran the legacy LAN driver package, rather than all GEEKOM mini PC owners.
However, GEEKOM has not disclosed how the malware infiltrated its servers, leaving open the possibility that the file was compromised before upload or that the hosting environment itself was later compromised. This scenario mirrors other instances where legitimate support software has been used as a persuasive delivery channel for malware, underscoring the need for users to exercise caution with older download links, even from trusted vendors.
In response, GEEKOM is in the process of removing the legacy files and pages and is implementing stricter review and resource management procedures. The company has also apologized to its users for the incident. While GEEKOM requested the original report be removed, the publication declined, emphasizing the importance of public awareness regarding such security lapses.
Users who may have downloaded the affected installer are strongly advised to delete it immediately and refrain from running it. Those who executed the file should perform a comprehensive scan with reputable anti-malware software. GEEKOM also recommends updating network drivers through official channels like Windows Update, the Realtek website, or GEEKOM's current support page. For users seeking maximum assurance, a clean Windows installation from Microsoft's official image is suggested.
The incident serves as a critical reminder for both end-users and organizations. Users should prioritize using current support portals accessed via main site navigation over old direct links or search results. Organizations should maintain a record of downloaded drivers, verify their sources, and scan all software before deployment to prevent the spread of compromised supply chains.
This event, while specific to GEEKOM's legacy support page, is part of a broader pattern of trusted update server compromises. It demonstrates how attackers exploit the inherent trust users place in vendor-provided software, turning legitimate channels into vectors for malicious payloads. The incident underscores the ongoing need for vigilance and robust security practices in managing software distribution and updates.