The Software You Never Installed Is Running on Your Machines
Key Intel / TL;DR
  • Plugging in certain LG monitors caused Windows Update to install an LG app with no consent prompt, and it pushed McAfee subscription ads on nearly every boot.
  • The install was triggered by device metadata, reached a three-year-old monitor, and ran on machines whose owners never asked for it.
  • The ads are a nuisance; the real risk is that software reached your endpoints outside every process you use to decide what runs there.
  • Your asset inventory tracks what you installed. It rarely tracks what a hardware vendor installed for you, which is a blind spot an attacker only needs once.
  • Treat the hardware-to-software boundary as a vendor risk decision: control auto-install, inventory what actually runs, and assess before you deploy.

Plug in a monitor and you expect a picture. You do not expect an application to install itself on your computer, run on almost every startup, and start showing you ads for antivirus you never asked for. That is what a number of people found their LG monitors doing this month.

Connecting certain LG displays to a Windows PC caused Windows Update to pull down an LG application through device metadata, with no consent prompt and no approval step (VideoCardz, PC Gamer). One reviewer, Gamers Nexus, tested it across 32 consecutive boots and watched a McAfee subscription promotion appear on 31 of them. The behavior reached a monitor bought three years earlier, which rules out a new-hardware quirk. This was software arriving on machines whose owners never chose it.

The ads are annoying. They are also not the point. The point is the door they came through.

The Ads Are the Symptom, Not the Disease

It is easy to file this under bloatware and move on. A monitor vendor made a deal to push antivirus promotions, someone will complain, and eventually it gets cleaned up. If that is where your attention stops, you have missed the part that should worry an operator.

Software installed itself on your endpoints, silently, triggered by an accessory, outside every process your organization uses to decide what runs on its machines.

That one sentence is the whole issue. You have a change management process. You have an approved software list. You have, somewhere, a person or a policy that decides what gets installed on company hardware. None of it was consulted. A peripheral was connected, and code you did not review, did not approve, and did not know about was fetched and run.

Today it served an ad. The mechanism that served the ad does not care what it delivers. The same silent path that dropped a promotional app is a path that could drop something with a worse payload, and it would arrive exactly as quietly.

Why Your Asset Inventory Is Lying to You

Every security program worth the name keeps an inventory of what is on its machines. The trouble is what that inventory actually measures. It measures what you put there. It tracks the operating system you imaged, the applications you deployed, the agents you installed. It is a record of your decisions.

This kind of install does not show up as one of your decisions, because it was not one. It rode in on device metadata from a monitor. Unless you are actively watching for software that appears without a corresponding change ticket, it sits on the endpoint as a thing that is simply there, unexplained and unquestioned.

That gap is not academic. An attacker does not need to defeat your whole fleet. They need one path onto one machine that nobody is looking at, and “software that installs itself when you plug in hardware” is a category most inventories were never built to see. You cannot protect what you do not know is running, and you cannot know it is running if your inventory only lists the things you meant to install. This is the same blind spot we write about in external attack surface management: the risk lives in the assets you forgot you had.

The Trust Boundary Nobody Drew

There is an assumption buried in how most organizations run their hardware. You buy a device, and you treat it as yours. The monitor is a monitor. The keyboard is a keyboard. The thing you paid for does the job you paid it to do, and nothing more.

That assumption is quietly false now, and this incident is a clean example of why. The vendor did not stop having a relationship with the hardware when the sale closed. Through device metadata and the update channel built into the operating system, the manufacturer kept a way to put software on your machine long after the box was opened. You own the monitor. The vendor kept a key to what runs alongside it.

This is a vendor risk question wearing a consumer-electronics costume. When you evaluate a software vendor, you ask what their product can access and what it does with that access. Hardware vendors have earned the same scrutiny, because the modern peripheral is a software delivery channel with a screen attached. The question is no longer only “is this monitor any good.” It is “what has this manufacturer reserved the right to install on the machines it connects to, and do I accept that.”

What To Actually Do About It

None of this means ripping out your monitors. It means treating the hardware-to-software boundary as something you manage on purpose rather than something you inherit by default. The work is mostly unglamorous, which is why it gets skipped.

Turn off metadata-driven auto-install. Windows has a setting for exactly this: a group policy called “Prevent installation of devices not described by other policy settings,” and more directly, the option to prevent Windows from automatically downloading apps and information linked to your devices. On a managed fleet, that belongs in your baseline image, not left at the default that let this happen. Decide what installs on your machines, and make the operating system ask you first.

Inventory what runs, not just what you deployed. The fix for a lying inventory is to measure reality instead of intention. Endpoint tooling that reports the actual installed software on each machine, compared against your approved list, turns “something appeared” into an alert instead of a surprise. The goal is simple: anything running that you did not put there should be a question, automatically, the day it shows up.

Put hardware vendors through real diligence. When you standardize on a monitor, a docking station, or any peripheral for the whole company, you are making a vendor decision at scale. Ask what the device installs, what update channels it uses, and whether it phones home. Testing one unit answers those questions before you buy a thousand of them, which is far cheaper than discovering the answer after they are on every desk. The peripheral is part of your supply chain, and it deserves the same review as any other link in it.

Watch the update channels you did not choose. Every automatic update path into your environment is a path an attacker would love to borrow. The operating system’s own update mechanism delivering third-party vendor software is one most teams never think to monitor. Know which ones are active, and treat an unexpected install through any of them as an incident to investigate, not a curiosity to ignore.

The Takeaway

LG will get the headlines for the ads, and the ads deserve the criticism. The lasting lesson is quieter and more useful. The line between the hardware you bought and the software running on your machines has gone soft, and most organizations are still operating as if it were solid.

Your defenses are built around a decision point: something wants to run, and you decide whether it may. This incident skipped that decision point entirely, and it did so through a channel you probably were not watching. That it delivered an ad this time is luck, not design.

The organizations that handle this well will not be the ones with the strictest hardware policy. They will be the ones who know, on any given day, exactly what is running on their machines and how it got there. That knowledge is a choice, and it is the one worth making before the next thing that installs itself is not selling antivirus.

If you cannot currently say what software rode onto your endpoints without a change ticket, that is the gap to close first. Contact Grab The Axe for an assessment that maps what is actually running across your fleet, or start with our free Human Attack Surface Score to see where the unmanaged paths into your organization run.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Author Page →