GCleaner is a Windows pay-per-install malware loader active since at least 2021. It has also been distributed under the name Garbage Cleaner, masquerading as a CCleaner-like system-cleaning utility. GCleaner retrieves and launches additional payloads from command-and-control infrastructure and has been observed distributing malware including Raccoon Stealer. It has been deployed through password-protected archives and trojanized installers promoted by SEO-poisoned websites offering cracked software, and has appeared in broader PPI delivery ecosystems alongside other commodity malware. Later PPI activity also delivered GCleaner to victims through gaming-themed and fake-software download lures. GCleaner has been observed on Windows systems and uses Windows networking and process-execution functionality to download and run follow-on binaries.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
« Une infection ultérieure (juin 2026) a livré GCleaner et Socks5Systemz via la même infrastructure. »
5 distinct techniques documented for this family, organized by ATT&CK tactic.
After a few redirections, the final payload is served to the user as a password-protected compressed (.zip) archive... It contained a Nullsoft Scriptable Install System (NSIS) installer named “setup_x86_x64_install.exe,” which embeds and executes numerous malicious payloads such as GCleaner, PrivateLoader and Redline.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Payload nommé livré lors d'une infection ultérieure par la même infrastructure PPI ; le contenu ne précise pas ses capacités.
A named payload delivered by the same OfferLoader-backed CL-CRI-1171 distribution infrastructure; the content provides no further technical characterization.
Pay-per-install loader previously distributed under a fake cleaner guise and used to download PUAs and stealers.
A pay-per-install loader observed among the campaign payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.