Breaking News

ENDORFY unveils new PC cases, keyboards, microphones and more at Computex 2025 KIOXIA Announces First Enterprise NVMe SSD Built with 8th Generation BiCS FLASH TLC-Based Flash Memory Technology MSI Unveils Groundbreaking Lineup at COMPUTEX 2025 ASUS Unveils White GeForce RTX 50 Series Graphics Cards TEAMGROUP Showcases Groundbreaking Innovation at COMPUTEX 2025

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Free CCleaner Software Compromised to Open Back-door to Million of PCs

Free CCleaner Software Compromised to Open Back-door to Million of PCs

Enterprise & IT Sep 18,2017 0

Hackers broke into Piriform's popular CCleaner software last month potentially allowing them to control the devices of more than two million users.

The free program CCleaner is downloaded for personal computers and Android phones as often as five million times a week. It allows users to perform routine maintenance on their systems. It includes functionality such as cleaning of temporary files, analyzing the system to determine ways in which performance can be optimized and provides a more streamlined way to manage installed applications. Piriform, which was bought in July by computer security vendor Avast, says that 130 million people use its software.

Security researchers at Cisco's Talos unit recently observed a case where the download servers used by software vendor to distribute a legitimate software package were leveraged to deliver malware to unsuspecting victims. For a period of time, the legitimate signed version of CCleaner 5.33 being distributed by Avast also contained a multi-stage malware payload that rode on top of the installation of CCleaner. CCleaner boasted over 2 billion total downloads by November of 2016 with a growth rate of 5 million additional users per week. Given the potential damage that could be caused by a network of infected computers even a tiny fraction of this size the security firm decided to move quickly. On September 13, 2017 Cisco Talos notified Avast of its findings so that they could initiate appropriate response activities.

The researchers identified a version of CCleaner downloaded in August, which included remote administration tools that tried to connect to several unregistered web pages, presumably to download additional unauthorized programs

The sophisticated attack penetrated an established and trusted supplier in a manner similar to June's "NotPetya" attack on companies that downloaded infected Ukrainian accounting software.

The optimization software had a proper digital certificate, which means that other computers automatically trust the program, the researchers said.

Piriform confirmed that two programs released in August were compromised. It advised users of CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 to download new versions. The company said that 2.27 million users had downloaded the August version of CCleaner while only 5,000 users had installed the compromised version of CCleaner Cloud.

A new version of CCleaner was released the same day and a clean version of CCleaner Cloud was released on Sept. 15, it said.

Piriform said it had worked with U.S. law enforcement to shut down a server located in the United States to which traffic was set to be directed.

This is a prime example of the extent that attackers are willing to go through in their attempt to distribute malware to organizations and individuals around the world. By exploiting the trust relationship between software vendors and the users of their software, attackers can benefit from users' inherent trust in the files and web servers used to distribute updates. In many organizations data received from commonly software vendors rarely receives the same level of scrutiny as that which is applied to what is perceived as untrusted sources. Attackers have shown that they are willing to leverage this trust to distribute malware while remaining undetected.

Tags: Hacking
Previous Post
Nokia Receives Decision in Patent License Arbitration with LG Electronics
Next Post
Samsung to Produce Its Own 1,000fps, 3-layer Image Sensor for Smartphones

Related Posts

  • MSI has been hacked, be warned about where you download files

  • Hackers gain access to PS5 Debug Menu and show decrypted PS5 firmware files

  • HP Threat Research Shows Attackers Exploiting Zero‐Day Vulnerability Before Enterprises Can Patch

  • EA Gets hacked - 780GB of data and sourcecode stolen

  • European Supercomputers Researching Covid-19 Report Hacking Attacks

  • Microsoft Offers You $100,000 If You Can Hack the Linux-based Azure Sphere

  • Zoom Users' Data have Been on Sale on Dark Web: report

  • Indonesia's Tokopedia Inverstigates Alleged Data Leak of 91 Million Users

Latest News

ENDORFY unveils new PC cases, keyboards, microphones and more at Computex 2025
PC components

ENDORFY unveils new PC cases, keyboards, microphones and more at Computex 2025

KIOXIA Announces First Enterprise NVMe SSD Built with 8th Generation BiCS FLASH TLC-Based Flash Memory Technology
Enterprise & IT

KIOXIA Announces First Enterprise NVMe SSD Built with 8th Generation BiCS FLASH TLC-Based Flash Memory Technology

MSI Unveils Groundbreaking Lineup at COMPUTEX 2025
Enterprise & IT

MSI Unveils Groundbreaking Lineup at COMPUTEX 2025

ASUS Unveils White GeForce RTX 50 Series Graphics Cards
GPUs

ASUS Unveils White GeForce RTX 50 Series Graphics Cards

TEAMGROUP Showcases Groundbreaking Innovation at COMPUTEX 2025
Enterprise & IT

TEAMGROUP Showcases Groundbreaking Innovation at COMPUTEX 2025

Popular Reviews

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Dark Rock 5

be quiet! Dark Rock 5

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

G.skill Trident Z5 Neo RGB DDR5-6000 64GB CL30

G.skill Trident Z5 Neo RGB DDR5-6000 64GB CL30

Arctic Liquid Freezer III 420 - 360

Arctic Liquid Freezer III 420 - 360

Crucial Pro OC 32GB DDR5-6000 CL36 White

Crucial Pro OC 32GB DDR5-6000 CL36 White

Crucial T705 2TB NVME White

Crucial T705 2TB NVME White

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed