GCleaner is a Windows pay-per-install malware loader used to download and execute additional payloads on compromised systems. It has also been referred to as Garbage Cleaner and has been observed masquerading as a fake system-cleaning utility, including branding that imitates legitimate cleaning software. The malware is part of the commodity cybercrime loader ecosystem and has been seen both as a standalone PPI loader and as a payload distributed by other malware delivery services such as PrivateLoader, NullMixer, and Amadey-linked campaigns.
GCleaner communicates with command-and-control infrastructure over HTTP, reports installation-related status information, and retrieves additional executables for local execution. Observed samples beacon to remote servers, transmit installation markers associated with BroomCleaner branding, download follow-on binaries, write them to temporary storage, and launch them via standard Windows execution APIs. In at least one analyzed case, the downloaded follow-on payloads were assessed as StealC samples, demonstrating GCleaner’s role as a malware delivery mechanism rather than an end-stage payload.
Distribution has been tied to malicious software-crack and fake-download ecosystems. It has been observed in campaigns using SEO poisoning and lure sites advertising cracked software, where victims are directed to password-protected archives containing installers that deploy multiple malware families. GCleaner has also been associated with fake cleaning-tool lures. Through these ecosystems it has been used alongside or in proximity to families such as Raccoon Stealer, RedLine, SmokeLoader, Vidar, and other commodity malware.
The malware targets Windows systems and is relevant across broad opportunistic victim populations rather than a single vertical. Its operational role is primarily initial payload delivery and staging for financially motivated cybercrime activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
After a few redirections, the final payload is served to the user as a password-protected compressed (.zip) archive... It contained a Nullsoft Scriptable Install System (NSIS) installer named “setup_x86_x64_install.exe,” which embeds and executes numerous malicious payloads such as GCleaner, PrivateLoader and Redline.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pay-per-install loader previously distributed under a fake cleaner guise and used to download PUAs and stealers.
A pay-per-install loader observed among the campaign payloads.
GCleaner is described as a known PPI loader and its presence reinforces that the operation is a malware installation marketplace.
Fake cleaning tool used as part of campaigns distributing AuraStealer (likely as a lure or trojanized installer); no further technical details provided.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.