GEEKOM Mini PC Driver Archive Contains Malware-Flagged LAN File

GEEKOM Mini PC owners should check driver archives immediately. A LAN driver file for AMD models is flagged as malware by multiple security engines.

GEEKOM Mini PC
GEEKOM Mini PC

GEEKOM Mini PC owners need to check their driver archives immediately. A network adapter file in the official download bundle triggers malware alerts across multiple antivirus engines. Users with -based models should pause any pending driver installations until they verify the file integrity. This alert highlights a security risk for numerous devices that were distributed with potentially compromised software components.

AMD-based models affected by compromised network adapter executable

The problematic executable is named Install_PCIe_Win11_11.10.0720.2022_11222022.exe. It resides in driver packages for AMD-based Mini PCs including the A7, A8, AE7, AE8, AX7 Pro, and AX8 Pro models. The file is designed to install a Local Area Network (LAN) driver for 11 systems. Security scanners flag this specific binary as a threat rather than a benign utility.

ClamAV identifies the file as Malware.Agentb. Additional detection engines report matches for Win.Trojan.Asruex variants. YARAify confirms these signatures and adds further Asruex detections to the list. No official statement from GEEKOM or a CVE number explains the presence of this code. The detections suggest the file contains malicious behavior patterns rather than simple false positives.

This security incident follows a similar pattern seen earlier in 2024. ACEMAGIC systems previously shipped Windows images that contained compromised software. The GEEKOM issue first surfaced on Reddit and traces back to December 2024. We looked at last Mini PC update when several of the same balance and stability themes came up.

Discussion

0 comments

Log in to join the thread with a thoughtful take, question, or correction.

Add to the discussion