Attackers compromised Piriform’s software production environment and distributed a malicious, validly signed build of CCleaner 5.33.6162—and affected CCleaner Cloud 1.07—to about 2.27 million systems between mid-August and mid-September 2017. Investigations by Avast, Talos, and Morphisec found the backdoored binary executed malicious code early in process initialization, performed host reconnaissance, contacted command-and-control infrastructure, and could receive additional payloads while using anti-debugging, reflective loading, and other evasion techniques. Avast revoked the signing certificate and released clean updates, first 5.34 and later 5.35, while urging users to upgrade and scan affected machines.
The compromise was later confirmed as a targeted espionage operation rather than indiscriminate malware distribution. Server logs and follow-on analysis showed second-stage malware was delivered to a small set of selected victims—initially reported as 20 machines across 8 organizations, later expanded to 40 PCs across 11 companies including Samsung, Sony, Asus, Intel, VMware, O2, Singtel, Gauselmann, Dyn, Chunghwa, and Fujitsu. Avast said the attackers had entered Piriform months earlier through TeamViewer access to a developer workstation, then moved laterally with RDP, credential theft, a keylogger, and ShadowPad until they reached a build server. Researchers noted code overlaps with activity previously associated with APT17, but said the evidence was insufficient for firm attribution.

Trace attribution and downstream blast radius.
19 events from the most recent confirmed update back to the earliest known activity.
Avast published new findings showing the attackers first accessed Piriform's network on March 11, 2017 via TeamViewer on a developer workstation, then moved laterally, used a keylogger, and deployed ShadowPad to four systems including a build server before the malicious CCleaner release.
Avast found a ShadowPad sample uploaded from South Korea to VirusTotal on December 27, 2017, configured to communicate with command-and-control servers hosted at Konkuk University.
Avast found a ShadowPad executable targeting a Russian organization involved in distributing public budgets; the sample was submitted to VirusTotal on November 3, 2017, with a related submission from China on November 6.
Avast Threat Labs released additional technical findings on September 22, 2017, covering the command-and-control server, second-stage payload structure, targeting changes, and inconclusive attribution clues including similarities to APT17-linked malware.
Avast reported that analysis of seized server data showed the CCleaner compromise was a targeted APT campaign and that a second-stage payload had been delivered to selected victims. It said 20 machines across 8 organizations appeared in a little over three days of logs and that the true number was likely higher.
Cisco Talos published its report on the CCleaner incident on September 18, 2017, publicly documenting the malware-tainted distribution of the software.
Avast said the malicious CCleaner 5.33.6162 build affected about 2.27 million computers between August 15 and September 15, 2017, marking the end of the known exposure window.
Avast said Cisco sent it a message about the CCleaner threat on September 14, 2017, after Morphisec's earlier notification.
On September 12, 2017, the attackers erased and reinstalled MariaDB and mariadb-server 5.5.52 on the command-and-control server after the earlier database failure.
Avast said it first learned of the possible malware from Morphisec on September 12, 2017, and a clean CCleaner 5.34 release was issued the same day to replace the compromised version.
Morphisec said some customers shared logs of the prevented malicious CCleaner activity with it on September 11, 2017.
Avast reported that the MariaDB database on the command-and-control server logged an InnoDB write failure on September 10, 2017 after the server ran out of disk space, corrupting stored victim data.
Morphisec said it identified and prevented malicious CCleaner.exe installations at customer sites on August 20 and 21, 2017, making it an early detector of the compromise.
The malicious CCleaner 5.33.6162 build was released on August 15, 2017, beginning the supply-chain distribution of the backdoored software. CCleaner Cloud version 1.07 was also affected.
Avast said data gathering on the attackers' server began on August 11, 2017 in preparation for releasing the compromised CCleaner executable.
Avast's later investigation said the first CCleaner build containing the malicious payload appeared on August 2, 2017, indicating attacker access to the build process before the broader release window described elsewhere.
Avast later found that the command-and-control server used in the CCleaner operation had been installed on July 31, 2017.
Avast acquired Piriform, the maker of CCleaner, in July 2017; one source specifies the acquisition date as July 18, 2017.
A September 25 update cited by WIRED said Avast confirmed that 40 computers received the secondary malware payload across 11 named companies, including Samsung, Sony, Asus, Intel, VMware, O2, Singtel, Gauselmann, Dyn, Chunghwa, and Fujitsu.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
7 references tracked. Mallory keeps watching after this page renders.
blog.morphisec.com
Open sourceblog.avast.com
Open sourceblog.avast.com
Open sourceblog.avast.com
Open sourcewired.com
Open sourceblog.talosintelligence.com
Open sourceblog.avast.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.