A malware campaign is using a fake CCleaner download site to infect Windows users with GhostDesk, a malicious Chrome extension that turns the browser into a surveillance and credential-theft platform. The installer triggers a multi-stage infection chain through cscript.exe, modifies Chrome’s Security Extension, and connects to attacker-controlled command-and-control infrastructure. Reporting indicates the operation also uses fake installers themed as 7-Zip and Adobe Acrobat, all tied to the same C2 domain.
Once installed, GhostDesk loads JavaScript components that enable keylogging, theft of credentials and cookies, screenshot capture, and clipboard manipulation targeting cryptocurrency strings. The malware can also inject scripts into web sessions and execute arbitrary JavaScript inside the browser, giving attackers broad visibility into victim activity and the ability to interfere with online transactions and account access.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Analysis showed the fake installer launched a multi-stage infection chain via cscript.exe, patched Chrome's Security Extension, and deployed JavaScript components that enabled keylogging, credential and cookie theft, screenshot capture, clipboard manipulation, script injection, and arbitrary JavaScript execution. The malware communicated with attacker infrastructure at liderongrade.duckdns[.]org and used local WebSocket relays for command handling and exfiltration.
Researchers found a malware campaign using a fake CCleaner installer from a lookalike site to infect Windows users with a malicious Chrome extension called GhostDesk. The campaign also included similarly themed fake 7-Zip and Adobe Acrobat installers connecting to the same command-and-control infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecsoonline.com
Open sourcemalwarebytes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.