Tech News

Geekom Support Site Offered a Malicious Network Driver Download

An executable found in the network driver archive offered on an older Geekom support page is being flagged as malicious by several analysis platforms, with detections pointing to the Asruex backdoor. Here’s what we know about this infection and its scope: who is actually affected?

An executable flagged by four analysis platforms

When downloading a driver, the best practice is to go straight to the source: the manufacturer’s official, trusted page. But that is not what happened here... The story began with a Reddit user report in mid-August 2026. Then several media outlets picked it up, starting with VideoCardz.

The issue: an archive available directly on Geekom’s website reportedly contained a driver infected with malware. The file in question is Install_PCIE_Win11_11.10.0720.2022_11222022.exe. It is located in the archive’s LAN driver folder and corresponds to a Realtek package intended for a PCIe network adapter. VideoCardz also took the time to download the archive and submit it to several analysis services: VirusTotal, FileScan.IO, MetaDefender, and YARAify.

Each time, a malicious family was detected: Malware.Agentb and Win.Trojan.Asruex, depending on the platform. Although the story is only making headlines now, this file hash was already being reported in December 2024. In other words, the file has been accessible for more than a year and a half.

The malware in question would be Asruex, which is not new and has been documented since October 2015, notably by JPCERT/CC and Trend Micro, which link it to the DarkHotel group. It is said to be a malware with backdoor capabilities, allowing it to download and execute files, as well as modify the Windows Registry.

Several media outlets describe malware running with admin privileges, capable of logging keystrokes, stealing passwords, and contacting a C2 server. These are in fact the known capabilities of this malware, not an analysis of the sample found in the driver. It is important to make that distinction. Above all, there is no public analysis showing which functions this file actually performs.

Not all Geekom PC models use this driver. In fact, Geekom generally provides a driver archive for several mini PC models. In this case, the archive targets the following PCs:

  • Geekom A7
  • Geekom A8
  • Geekom AE7
  • Geekom AE8
  • Geekom AX7 Pro
  • Geekom AX8 Pro

As you know, I have tested many Geekom mini PCs, including some on this list, such as the A7 and A8. I have already had to download the Geekom A8 driver archive after a reinstall, but I did not get any alerts from Windows Defender. That said, the facts are real, but I could not have written about this earlier since I had not encountered this situation myself.

Geekom apologizes, without explaining where the file came from

This story made waves across the web, forcing the Taiwanese manufacturer to respond. An official press release was published on August 18, 2026. Geekom explains that it simply failed to clean up its website: "This issue stems from an outdated resource that we did not remove from our old pages in time," the company says.

From what I understand, this appears to have been an old support page no longer linked from Geekom’s website but still indexed by search engines. As a result, a Geekom driver search on Google could lead you to that page: something many of us would do rather than digging through the menus on the official website.

That explanation is plausible. However, one major gray area remains: Geekom does not explain how this file ended up on its infrastructure. Doubt still remains, and all possibilities are open: server compromise, a previously infected third-party component retrieved from a supplier, or a false positive... We do not know. It is also fair to ask whether this infected file is distributed by other brands or other platforms (DriversCloud, for example).

What should you do if you downloaded this driver?

Be aware that Geekom insists the Windows image shipped by default on its mini PCs is not infected by this malicious driver. Owning a device from the brand does not mean you are infected.

The risk mainly concerns you if you downloaded the driver archive after a Google search that led you to the wrong page... which may have happened after a full Windows reinstall from an official ISO image (although the most convenient option is usually to export drivers with DISM).

If that is the case, it is recommended that you perform a full scan of your PC with a security solution (Microsoft Defender at minimum). Then reinstall the driver by downloading it directly from Geekom’s website (use this page). If you downloaded this archive, the ideal solution is to completely reinstall your system using the ISO image from Microsoft’s website.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.