600 MAC’s from one vendor. I would like to have a look at that list (not gone looking for it yet).
I wonder if the MAC’s are close together, maybe just a block of 600 (I.e XX:XX:XX:XX:XA:AA TO xx:XX:XX:XX:XB:BB instead of a list of 600 hashes embedded)?
If so I would suspect that the attacker was aware of a company purchasing a number of machines from ASUS, had access to one of those machines in one way or another. Knew someone important had a machine from that batch and burnt access to a hardware vendors signing key to gain access...
But it raises so many questions. How were ASUS storing their signing keys? How did the attacker gain access to the signing key and access the updates server (though if they had crap cert/key security it’s not that much of a jump to presume they didn’t look after their updates servers either). And why would they burn that access over such a small number of possible targets (instead of say, infecting every machine with a bad update that a) stops future updates b) encrypted the users data and then wipes out the UEFI of every infected machine if a ransom isn’t paid by X date? Think of the damage to a brand if 10,000 (a low number of machines that ran the payload according to the article) destroyed and bricked it’s customers data and machine all at the same time? Would they refuse to pay up?
All I’m saying is, access to that small number of machines much of been worth a decent amount to the attackers to burn access to a large vendors update servers and signing keys...
EDIT: Wait a minute....
> The attackers used two different ASUS digital certificates to sign their malware. The first expired in mid-2018, so the attackers then switched to a second legitimate ASUS certificate to sign their malware after this.
So they were in for a fair amount of time for a code signing cert to expire on them so they needed access to a 2nd... Ouch.