Site navigation

CCleaner: A Vast Infection

Andrew Hamilton

,

CCleaner has been compromised

The popular disk cleaner, downloaded as often as five million times per week, was rigged by hackers to collect information from infected computers, says Cisco.

A recent release of popular disk utility CCleaner contained malware according to Cisco’s Security Intelligence and Research Group Talos.

The application, distributed by Piriform, a subsidiary of cyber-security giant Avast, was created to optimise computer performance and clear temporary files where malicious software likes to reside. However, more than two million users’ devices may have been compromised since last month after hackers snuck data mining malware into the product.

Talos claims that two CCleaner versions (v5.33.6162 and CCleaner Cloud v1.07.3191) included remote administration tools which attempted to connect to several unregistered web pages, presumably to download additional malicious programs. The release was hosted on the CCleaner site for around one month between August 15th and September 11th, but was discovered to be malicious after the Talos team ran diagnostics on the product, concluding on September 13th.  Talos claims to have notified Piriform immediately.

In a blog post, Piriform confirmed that an attack had been staged and up to 2.27 million users had downloaded the compromised software, however the firm, ‘believes no harm was done to any of our users’. As a safety precaution, the firm urged users to update their versions of CCleaner to the latest release. At the time when Avast purchased Piriform in July, more than 130 million people had downloaded CCleaner.

The software engineers at Talos said in a blog post charting their research: “The impact of this attack could be severe given the extremely high number of systems possibly affected. CCleaner claims to have over 2 billion downloads worldwide as of November 2016 and is reportedly adding new users at a rate of 5 million a week. If even a small fraction of those systems were compromised an attacker could use them for any number of malicious purposes.”

The Talos engineers branded this infection a, ‘supply chain attack’, as it intercepted a known product and piggybacked on the trust between a company and its customers. This breed of sophisticated attack was given prominence earlier this year in June, when ‘NotPetya’ malware was spread by companies that had downloaded infected Ukrainian accounting software. Talos noted that the particular install of CCleaner also came with a valid digital certificate, meaning computers flagged the product as trustworthy to users.

Piriform confirmed that it is working with US law enforcement to determine who was behind the breach. The firm also claimed that US authorities have already closed a Stateside server which was receiving traffic from the afflicted application.

The engineers at Talos said: “This is a prime example of the extent that attackers are willing to go through in their attempt to distribute malware to organizations and individuals around the world. By exploiting the trust relationship between software vendors and the users of their software, attackers can benefit from users’ inherent trust in the files and web servers used to distribute updates.

“In many organizations data received from commonly software vendors rarely receives the same level of scrutiny as that which is applied to what is perceived as untrusted sources. Attackers have shown that they are willing to leverage this trust to distribute malware while remaining undetected.”

Andrew Hamilton

Andrew Hamilton

PR & Content Executive at Hutchinson Networks

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data