News

Geekom Mini PC Malware Scare: Check If Your Device Is Affected

4 min read Editorial

Geekom has confirmed a security incident affecting several of its popular mini PC models, where attackers managed to inject malware into driver packages hosted on an outdated support page. The breach highlights a critical vulnerability in how users often source drivers for their hardware, relying on search engine results rather than direct manufacturer verification.

According to reports from Tom’s Hardware and Videocardz, the attackers exploited a legacy version of the Geekom support website. Even though the company replaced the outdated site, search engines continued to index the old pages, allowing malicious actors to tamper with driver files and distribute them to unsuspecting users.

Which Geekom Models Are Affected?

Geekom identified a specific list of mini PC models that were at risk during the window when the compromised drivers were available. If you own one of these devices, your exposure depends entirely on whether you manually downloaded a driver from the tainted source.

Advertisement

The affected models include:

  • Geekom A7
  • Geekom A8
  • Geekom AE7
  • Geekom AE8
  • Geekom AX7 Pro
  • Geekom AX8 Pro

It is important to note that Geekom’s current official driver packages do not contain malware. The risk was isolated to the specific driver files hosted on the deprecated website that was accessible via search engine caches.

A close-up shot of a mini PC chassis highlighting its ventilation grilles and ports, shot with a shallow depth of field
The Geekom A7 and A8 models were among those flagged in the driver tampering incident.

How the Attack Worked

The incident began when attackers gained access to the old Geekom support portal. They modified a network driver package by inserting a backdoor, which allowed them to install malicious software on the user’s system upon installation.

Because many users search for “[device name] driver update” and click the first result, the tampered file from the old site often appeared at the top of search listings. Once installed, the malware granted attackers extensive permissions, enabling them to spy on personal data and steal passwords.

Geekom has since taken the outdated site offline and replaced it with a new, secure support portal. However, the persistence of old pages in search engine indexes remains a common vector for similar attacks across the tech industry.

What This Means for You

If you own a Geekom mini PC, the immediate concern is whether you downloaded a driver from the compromised source. If you used Windows Update or downloaded drivers directly from the new Geekom support page, your device is likely safe.

However, if you performed a manual search for drivers in the past and installed them from an older URL, you should treat your system as potentially compromised. The malware’s ability to capture passwords and monitor activity means that any credentials entered on the affected device should be considered exposed.

An abstract digital illustration of a network shield protecting a data stream, using cool blue and green tones to repres
Users are advised to run full system scans if they suspect their drivers were compromised.

How to Check and Secure Your Device

Geekom and security experts recommend the following steps to verify your system’s integrity and remove any potential threats:

1. Run a Full Malware Scan

Launch your antivirus software immediately and perform a thorough, full-system scan. If you do not have a robust antivirus solution, consider using a reputable second-opinion scanner to check for the specific backdoor associated with this incident.

2. Check Driver Installation Dates

You can use the Windows Device Manager to review when drivers were installed. Open Device Manager, right-click on your network adapters and other critical components, and check the driver properties for installation dates. If a driver was updated during the timeframe of the incident from an unknown source, it may be the vector for the attack.

3. Disconnect and Factory Reset

If you suspect your device is infected, disconnect it from your network immediately to prevent data exfiltration. The most reliable way to ensure the malware is removed is to perform a factory reset. This will wipe the system and restore it to its original state.

4. Change Your Passwords

After resetting your device, change all passwords that you entered on the affected Geekom mini PC. This includes email, banking, and social media accounts. Enable two-factor authentication wherever possible to add an extra layer of security.

Preventing Future Driver Issues

This incident serves as a reminder to always download drivers from official sources. While Geekom’s new site is secure, the broader lesson is to avoid relying on search engine results for critical software updates. Navigate directly to the manufacturer’s support page rather than clicking on the first result in a search query.

By staying vigilant and following these security practices, you can protect your hardware and personal data from similar threats in the future.

Source: PCWorld

Over to you: If you own a Geekom mini PC, have you already checked your driver history for any suspicious installations?

Advertisement
Share:
Editorial
Written by
Editorial

Windows & Microsoft news editor at 9to5Windows. Covering everything from Windows 11 builds to enterprise updates.

Advertisement