Connect with us

Hi, what are you looking for?

Tech & Science

Avast’s popular PC-cleaning software has been hacked

It has been discovered that Piriform’s CCleaner, owned by antivirus provider Avast, was found to be hosting a “multi-stage malware payload” that could install ransomware or keyloggers and further infect target computers on command, according to an analysis by threat intelligence firm Cisco Talos

“For a period of time, the legitimate signed version of CCleaner 5.33 being distributed by Avast also contained a multi-stage malware payload that rode on top of the installation of CCleaner,” Cisco Talos said in a statement. According to Avast, about 2.27 million people ran the hacked software which was downloaded from an infected server.

The malware was discovered by Cisco Talos on September 13, and Avast was notified immediately. “During the installation of CCleaner 5.33, the 32-bit CCleaner binary that was included also contained a malicious payload that featured a Domain Generation Algorithm (DGA) as well as hardcoded Command and Control (C2) functionality. We confirmed that this malicious version of CCleaner was being hosted directly on CCleaner’s download server as recently as September 11, 2017,” said Cisco Talos.

The impact from the malware could have been more damaging than it was. CCleaner has been downloaded more than 2 billion times according to Avast, making it a popular target for hackers. Dubbed the “crap cleaner,” it’s designed to remove rogue programs and wipe out cookies and offer some web privacy protections.

“By exploiting the trust relationship between software vendors and the users of their software, attackers can benefit from users’ inherent trust in the files and web servers used to distribute updates,” said Cisco Talos researchers, in a blog post, reports Engadget.

Talos says the attack vector isn’t new, but it is being seen more frequently in the last few months. The virus is a version of the “Petya” ransomware and like the WannaCry virus that wreaked international havoc in May, it appears to take advantage of a Microsoft Windows flaw uncovered by the NSA and published online by hackers.

Digital Signature of CCleaner 5.33

Digital Signature of CCleaner 5.33
Cisco Talos


At one time, hackers would make fake alternatives of popular applications and trick people into downloading them. Now, it’s easier to attack the download source, gaining access into legitimate servers. It’s a trend that many security researchers will be monitoring closely, to catch the latest innovative ways that hackers are breaching multiple systems, according to the Verge.

“This is a prime example of the extent that attackers are willing to go through in their attempt to distribute malware to organizations and individuals around the world,” Cisco Talos warns. “Attackers have shown that they are willing to leverage this trust to distribute malware while remaining undetected.”

Avatar photo
Written By

We are deeply saddened to announce the passing of our dear friend Karen Graham, who served as Editor-at-Large at Digital Journal. She was 78 years old. Karen's view of what is happening in our world was colored by her love of history and how the past influences events taking place today. Her belief in humankind's part in the care of the planet and our environment has led her to focus on the need for action in dealing with climate change. It was said by Geoffrey C. Ward, "Journalism is merely history's first draft." Everyone who writes about what is happening today is indeed, writing a small part of our history.

You may also like:

World

US President Joe Biden delivers remarks after signing legislation authorizing aid for Ukraine, Israel and Taiwan at the White House on April 24, 2024...

World

AfD leaders Alice Weidel and Tino Chrupalla face damaging allegations about an EU parliamentarian's aide accused of spying for China - Copyright AFP Odd...

Business

Meta's growth is due in particular to its sophisticated advertising tools and the success of "Reels" - Copyright AFP SEBASTIEN BOZONJulie JAMMOTFacebook-owner Meta on...

Business

Tony Fernandes bought AirAsia for a token one ringgitt after the September 11 attacks on the United States - Copyright AFP Arif KartonoMalaysia’s Tony...