Fake CCleaner Installer Distributes GhostDesk Spyware in Targeted Campaign
Cybercriminals are exploiting the popularity of CCleaner a widely trusted PC-cleaning utility with over 2 billion downloads to distribute GhostDesk, a malicious Chrome extension designed to spy on browsing activity and steal sensitive data.
The attack begins with a fraudulent website, ccleanerwind[.]top, which mimics the legitimate CCleaner download page. Visitors are presented with options for both the free and Pro versions of the software, but all download buttons deliver the same malicious executable CCleaner.exe disguised with the real application’s icon. However, the file’s metadata reveals inconsistencies, including an internal name (svc_it7p) and original filename (rt_mxk.exe) that differ from authentic CCleaner releases. Researchers have also identified similarly named variants following patterns like svc_
Once executed, the fake installer initiates a multi-stage infection chain that modifies Google Chrome and deploys spyware components. The malware first drops and runs cscript.exe, a legitimate Windows scripting tool, to gather system details such as the machine GUID, device name, and language settings. It then replaces a file at %AppData%\Microsoft\DriverStore\runtimebroker.dll with a reflexive loader, enabling the execution of additional malicious code.
A critical step in the attack involves tampering with Chrome’s Security Extension manifest file (manifest.json). The malware injects two scripts background.js (a background service worker) and content.js (a content script) stored in %LocalAppData%\cse. These components establish persistence and facilitate data exfiltration.
The infection also sets up command-and-control (C2) communication, creating a local WebSocket endpoint at 192.168.100.4:49727 before connecting to the attacker-controlled domain liderongrade.duckdns[.]org on port 4444. This channel allows the malware to receive instructions and transmit stolen information.
The final payload, GhostDesk, masquerades as legitimate screen-overlay software. When Chrome launches, background.js loads silently, while content.js monitors and logs keystrokes entered into web forms. Captured data is buffered and sent to the C2 server after two seconds of inactivity or when the user switches fields.
The campaign leverages CCleaner’s reputation to evade suspicion, underscoring the risks of trust-based social engineering in malware distribution. Indicators of compromise include the fraudulent domain ccleanerwind[.]top and the C2 domain liderongrade.duckdns[.]org.
Source: https://cyberpress.org/fake-ccleaner-spreads-ghostdesk/
CCleaner TPRM report: https://www.rankiteo.com/company/ccleaner
"id": "ccl1786525619",
"linkid": "ccleaner",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Users who downloaded the fake '
'installer from '
'ccleanerwind[.]top',
'industry': 'Software/Utilities',
'location': 'Global',
'name': 'CCleaner (Brand Misuse)',
'type': 'Software Brand'}],
'attack_vector': 'Fraudulent Website (Phishing)',
'data_breach': {'data_exfiltration': 'Yes (to C2 server '
'liderongrade.duckdns[.]org)',
'personally_identifiable_information': 'Yes (if entered in '
'monitored web forms)',
'sensitivity_of_data': 'High (Personally Identifiable '
'Information, Payment Information)',
'type_of_data_compromised': ['Browsing activity',
'Keystrokes',
'Sensitive form data']},
'description': 'Cybercriminals are exploiting the popularity of CCleaner, a '
'widely trusted PC-cleaning utility with over 2 billion '
'downloads, to distribute GhostDesk, a malicious Chrome '
'extension designed to spy on browsing activity and steal '
'sensitive data. The attack begins with a fraudulent website, '
'ccleanerwind[.]top, which mimics the legitimate CCleaner '
'download page. The malware initiates a multi-stage infection '
'chain that modifies Google Chrome and deploys spyware '
'components, enabling data exfiltration and '
'command-and-control communication.',
'impact': {'brand_reputation_impact': 'Potential reputational damage to '
'CCleaner due to misuse of its brand',
'data_compromised': 'Browsing activity, keystrokes, sensitive data '
'from web forms',
'identity_theft_risk': 'High (due to keystroke logging and data '
'exfiltration)',
'payment_information_risk': 'High (if payment details were entered '
'in monitored web forms)',
'systems_affected': 'Windows systems with Google Chrome installed'},
'initial_access_broker': {'backdoors_established': 'Reflexive loader '
'(runtimebroker.dll), '
'WebSocket C2 '
'communication',
'entry_point': 'Fraudulent website '
'(ccleanerwind[.]top)'},
'lessons_learned': 'The incident highlights the risks of trust-based social '
'engineering and the importance of verifying download '
'sources, even for trusted software brands.',
'motivation': 'Data Theft, Espionage',
'post_incident_analysis': {'corrective_actions': 'Enhanced monitoring of '
'brand misuse, user '
'education on secure '
'download practices, '
'improved detection of '
'malicious browser '
'extensions',
'root_causes': 'Exploitation of brand trust, lack '
'of user verification of download '
'sources, malicious Chrome '
'extension injection'},
'recommendations': ['Verify the authenticity of download sources before '
'installing software.',
'Monitor for unusual modifications to browser extensions '
'or system files.',
'Use endpoint detection and response (EDR) tools to '
'identify malicious activity.',
'Educate users on recognizing phishing and fraudulent '
'websites.'],
'references': [{'source': 'Cybersecurity Research Report'}],
'title': 'Fake CCleaner Installer Distributes GhostDesk Spyware in Targeted '
'Campaign',
'type': 'Malware Distribution',
'vulnerability_exploited': 'Trust-based Social Engineering'}