CCleaner is a legitimate Windows system-cleaning utility that was abused in a major supply-chain compromise in 2017, when attackers distributed a trojanized version containing a backdoor. The malicious code collected basic host information from infected systems and communicated with attacker-controlled infrastructure to receive additional payloads. A selectively deployed second-stage component was delivered to a small set of high-value targets and used legitimate signed software components as cover while loading patched DLLs. Those DLLs stored malware in the Windows registry, executed a concealed loader, and supported retrieval of further command-and-control information through multiple fallback mechanisms including web content and DNS-based derivation. The second stage could exfiltrate host details and download and execute a third-stage payload.
The operation is widely regarded as a notable software supply-chain intrusion affecting Windows environments and targeting selected technology and industrial organizations. Code similarities with malware associated with APT17 were observed, but public reporting did not establish reliable attribution with high confidence. Separately, CCleaner has also been used by threat actors as a legitimate utility for anti-forensic cleanup and deletion of artifacts on compromised systems, but that behavior is distinct from the trojanized CCleaner malware involved in the supply-chain attack.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The backdoor in CCleaner called home to receive the second stage payload which we found in the server dump under the name GeeSetup_x86.dll.
APT28 has intentionally deleted computer files to cover their tracks, including with use of the program CCleaner.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
System cleaning utility referenced as being abused by ransomware actors for artifact removal/anti-forensics.
Referenced as a compromised software supply-chain case used as an example of how trusted application updates can be weaponized for cyberattacks.
A compromised CCleaner build contained a backdoor that contacted a C2 server, uploaded victim information, and fetched a second-stage payload used for further targeting and execution of additional malware.
Legitimate system-cleaning utility abused for anti-forensics by deleting files to cover attacker activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.