CCleanup downloads piggyback malware

For discussions about security.
Post Reply
Message
Author
User avatar
Flash
Official Dog Handler
Posts: 13071
Joined: Wed 04 May 2005, 16:04
Location: Arizona USA

CCleanup downloads piggyback malware

#1 Post by Flash »

CCleanup: A Vast Number of Machines at Risk
Talos recently observed a case where the download servers used by software vendor to distribute a legitimate software package were leveraged to deliver malware to unsuspecting victims. For a period of time, the legitimate signed version of CCleaner 5.33 being distributed by Avast also contained a multi-stage malware payload that rode on top of the installation of CCleaner. CCleaner boasted over 2 billion total downloads by November of 2016 with a growth rate of 5 million additional users per week.
I assume that CCleanup is a Windows-based program only, so this malware only affects Windows. Still, it just goes to show that you can't be too careful out there. Always wear your galoshes and carry an umbrella -- and a pistol for good measure. :lol:

User avatar
6502coder
Posts: 677
Joined: Mon 23 Mar 2009, 18:07
Location: Western United States

Technical details

#2 Post by 6502coder »

A good technical discussion can be found here:
http://blog.talosintelligence.com/2017/ ... lware.html

bark_bark_bark
Posts: 1885
Joined: Tue 05 Jun 2012, 12:17
Location: Wisconsin USA

Re: CCleanup downloads piggyback malware

#3 Post by bark_bark_bark »

Flash wrote:CCleanup: A Vast Number of Machines at Risk
Talos recently observed a case where the download servers used by software vendor to distribute a legitimate software package were leveraged to deliver malware to unsuspecting victims. For a period of time, the legitimate signed version of CCleaner 5.33 being distributed by Avast also contained a multi-stage malware payload that rode on top of the installation of CCleaner. CCleaner boasted over 2 billion total downloads by November of 2016 with a growth rate of 5 million additional users per week.
I assume that CCleanup is a Windows-based program only, so this malware only affects Windows. Still, it just goes to show that you can't be too careful out there. Always wear your galoshes and carry an umbrella -- and a pistol for good measure. :lol:
Ccleaner is owned by Avast now, so that's just a good enough reason to stay away from it.
....

User avatar
Tag365
Posts: 18
Joined: Tue 29 Nov 2016, 23:08

Re: CCleanup downloads piggyback malware

#4 Post by Tag365 »

bark_bark_bark wrote: Ccleaner is owned by Avast now, so that's just a good enough reason to stay away from it.
I thought that Avast was considered a good company. Why are they distributing malware in the download?

User avatar
Flash
Official Dog Handler
Posts: 13071
Joined: Wed 04 May 2005, 16:04
Location: Arizona USA

Re: CCleanup downloads piggyback malware

#5 Post by Flash »

Tag365 wrote:...Why are they distributing malware in the download?
Giving them the benefit of the doubt, they probably had no idea their server and certificate had been pwned and a malicious payload added to the download.

User avatar
8Geee
Posts: 2181
Joined: Mon 12 May 2008, 11:29
Location: N.E. USA

a little clarity here

#6 Post by 8Geee »

USA Today has an article about it

https://www.usatoday.com/story/tech/tal ... 678277001/#

This was a hack of known good SW. It was/is apparantly targetting Android users.

Sorry, I won't hot link, Ctrl C&V please. THanks

Regards
8Geee
Linux user #498913 "Some people need to reimagine their thinking."
"Zuckerberg: a large city inhabited by mentally challenged people."

Post Reply