Geekom has confirmed a security incident affecting several of its popular mini PC models, where attackers managed to inject malware into driver packages hosted on an outdated support page. The breach highlights a critical vulnerability in how users often source drivers for their hardware, relying on search engine results rather than direct manufacturer verification.
According to reports from Tom’s Hardware and Videocardz, the attackers exploited a legacy version of the Geekom support website. Even though the company replaced the outdated site, search engines continued to index the old pages, allowing malicious actors to tamper with driver files and distribute them to unsuspecting users.
Which Geekom Models Are Affected?
Geekom identified a specific list of mini PC models that were at risk during the window when the compromised drivers were available. If you own one of these devices, your exposure depends entirely on whether you manually downloaded a driver from the tainted source.
The affected models include:
- Geekom A7
- Geekom A8
- Geekom AE7
- Geekom AE8
- Geekom AX7 Pro
- Geekom AX8 Pro
It is important to note that Geekom’s current official driver packages do not contain malware. The risk was isolated to the specific driver files hosted on the deprecated website that was accessible via search engine caches.

How the Attack Worked
The incident began when attackers gained access to the old Geekom support portal. They modified a network driver package by inserting a backdoor, which allowed them to install malicious software on the user’s system upon installation.
Because many users search for “[device name] driver update” and click the first result, the tampered file from the old site often appeared at the top of search listings. Once installed, the malware granted attackers extensive permissions, enabling them to spy on personal data and steal passwords.
Geekom has since taken the outdated site offline and replaced it with a new, secure support portal. However, the persistence of old pages in search engine indexes remains a common vector for similar attacks across the tech industry.
What This Means for You
If you own a Geekom mini PC, the immediate concern is whether you downloaded a driver from the compromised source. If you used Windows Update or downloaded drivers directly from the new Geekom support page, your device is likely safe.
However, if you performed a manual search for drivers in the past and installed them from an older URL, you should treat your system as potentially compromised. The malware’s ability to capture passwords and monitor activity means that any credentials entered on the affected device should be considered exposed.

How to Check and Secure Your Device
Geekom and security experts recommend the following steps to verify your system’s integrity and remove any potential threats:
1. Run a Full Malware Scan
Launch your antivirus software immediately and perform a thorough, full-system scan. If you do not have a robust antivirus solution, consider using a reputable second-opinion scanner to check for the specific backdoor associated with this incident.
2. Check Driver Installation Dates
You can use the Windows Device Manager to review when drivers were installed. Open Device Manager, right-click on your network adapters and other critical components, and check the driver properties for installation dates. If a driver was updated during the timeframe of the incident from an unknown source, it may be the vector for the attack.
3. Disconnect and Factory Reset
If you suspect your device is infected, disconnect it from your network immediately to prevent data exfiltration. The most reliable way to ensure the malware is removed is to perform a factory reset. This will wipe the system and restore it to its original state.
4. Change Your Passwords
After resetting your device, change all passwords that you entered on the affected Geekom mini PC. This includes email, banking, and social media accounts. Enable two-factor authentication wherever possible to add an extra layer of security.
Preventing Future Driver Issues
This incident serves as a reminder to always download drivers from official sources. While Geekom’s new site is secure, the broader lesson is to avoid relying on search engine results for critical software updates. Navigate directly to the manufacturer’s support page rather than clicking on the first result in a search query.
By staying vigilant and following these security practices, you can protect your hardware and personal data from similar threats in the future.
Source: PCWorld
Over to you: If you own a Geekom mini PC, have you already checked your driver history for any suspicious installations?



