Breaking Lab srl
Hidden in the Driver You Never Thought to Check
Most people worry about downloading dodgy files from the internet. Far fewer think to question the software that ships on a brand-new computer straight from the factory. That is exactly the gap that a recently discovered threat exploits. Several Geekom mini-PC models — compact desktop computers popular with home users and small offices — were found to contain a malicious executable buried inside the installer for a LAN driver (the software that connects the PC to a wired network).
The hidden file is capable of logging keystrokes (recording every key you press, including passwords), intercepting data passing through the machine, and stealing credentials stored on the device. Because it hides inside a legitimate driver package, standard caution like “only download from trusted sources” offers no protection — the threat came with the machine.
What Makes This Particularly Uncomfortable
This is a supply chain attack, meaning the compromise happened somewhere between the manufacturer and the end user, before the device ever reached you. Supply chain attacks are serious because they undermine the basic assumption that hardware bought new from a reputable retailer is clean. You cannot scan your way out of a threat you do not know is there.
Making things worse, Geekom has reportedly pushed responsibility for the fix onto owners themselves. There is no automatic update coming. If you own an affected device, you need to identify and remove the malicious component manually — or with the help of a security tool capable of finding it.
What You Should Do Right Now
If you own a Geekom mini-PC, especially one purchased in the last couple of years, treat it as potentially compromised until you have checked. Run a full scan with a reputable anti-malware tool — one that scans drivers and startup files, not just downloads. Change any passwords you may have typed on the machine, particularly for email, banking, and hosting control panels. Enable two-factor authentication (a second login step, usually a code sent to your phone) on any important accounts as an extra barrier even if a password was stolen.
If you use the machine as a home server or for anything business-related, consider it a higher priority. Keystroke loggers on a machine running a web server or storing client data are a serious liability.
The Bigger Picture
This incident is a reminder that the hardware supply chain has become an attack surface in its own right. Regulators in several countries are beginning to push for minimum security standards on consumer hardware, but those rules are not yet in place. For now, the safest habit when setting up any new device is to update or reinstall all drivers from the manufacturer’s official website before doing anything else — and to run a security scan before you trust it with a single password.







