Domestic mini PC manufacturer GEEKOM was recently discovered to be distributing driver downloads through its official website that contained a backdoor. A Reddit user first spotted the anomaly and posted a warning, after which outlets including VideoCardz independently downloaded and tested the corresponding drivers from GEEKOM’s official site, confirming that driver packages for several of the company’s AMD-based mini PC models were indeed infected.
Infected Packages Have Been Live Since December 2024
Based on current evidence, this does not appear to be malware deliberately distributed by GEEKOM itself. Rather, GEEKOM’s website infrastructure was compromised, allowing attackers to tamper with driver packages. The affected models include the A7, A8, AE7, AE8, AX7 Pro, and AX8 Pro. The backdoor was ultimately placed inside the LAN driver folder, under the filename Install_PCIE_Win11_11.10.0720.2022_11222022.exe.
Notably, the compromise dates back at least to December 2024, yet GEEKOM failed to detect the infiltration of its own infrastructure for an extended period. This delay stems from how the company manages its site: the attackers specifically tampered with download links on an older, legacy support page. Users who navigated to GEEKOM’s official website and clicked through its current support or download sections would never have encountered the compromised page.
The problem instead arose for users who searched for GEEKOM drivers directly through Google. Google’s search index continued surfacing the outdated legacy driver download page, leading unsuspecting users straight to the compromised page – and, consequently, to the backdoored driver.
GEEKOM Asked VideoCardz to Remove Its Report – and Was Refused
After VideoCardz published its report, the GEEKOM team reached out to explain the circumstances behind the incident while simultaneously requesting that VideoCardz take the article down. VideoCardz declined, stating that its reporting contained no factual errors and that removing an accurate article outright would be inappropriate unless the entire piece were proven incorrect.
In its response, GEEKOM did not disclose exactly how the backdoored driver made its way onto the legacy download page, leaving it unclear whether this was the result of a supply-chain attack or a direct compromise of the company’s web servers. Similar incidents in the past have typically involved supply-chain attacks – smaller OEMs lacking in-house driver development capability outsource that work downstream, and the resulting driver package becomes infected somewhere during delivery, sometimes even through an infected USB drive used to transfer files from an already-compromised build machine.
GEEKOM Recommends a Full System Reinstall for Affected Users
In its response, GEEKOM advised users to run a full antivirus scan across their system, and even suggested downloading a clean image and performing a complete operating system reinstall to guarantee safety. Users who actively searched for GEEKOM drivers via Google and downloaded them directly are specifically advised to reinstall their systems. Drivers that came pre-installed on GEEKOM devices from the factory remain unaffected, so users who never manually downloaded and installed GEEKOM drivers should generally be safe – though running a full system scan to rule out any anomalies is still recommended.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.