{"id":9113,"date":"2026-08-12T11:26:50","date_gmt":"2026-08-12T11:26:50","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9113"},"modified":"2026-08-12T11:26:50","modified_gmt":"2026-08-12T11:26:50","slug":"fake-ccleaner-downloads-turn-chrome-into-a-credential-stealing-surveillance-tool","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9113","title":{"rendered":"Fake CCleaner downloads turn Chrome into a credential-stealing surveillance tool"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">A convincing fake version of the widely used CCleaner utility is being used to deliver a multi-stage Windows malware that ultimately abuses Google Chrome for credential theft and surveillance.<\/p>\n<p class=\"wp-block-paragraph\">Researchers from Malwarebytes found the campaign distributing a malicious Chrome extension called GhostDesk, which can capture credentials, cookies, keystrokes, and screenshots while also allowing attackers to inject arbitrary JavaScript into active browser tabs.<\/p>\n<p class=\"wp-block-paragraph\">Attackers created a lookalike CCleaner download site and used it to distribute a malicious \u201cCCleaner.exe,\u201d researcher <a href=\"https:\/\/www.linkedin.com\/in\/sav-wheeler-80b1b2271\/\" target=\"_blank\" rel=\"noopener\">Sav Wheeler<\/a> said in a blog <a href=\"https:\/\/www.malwarebytes.com\/blog\/threat-intel\/2026\/08\/fake-ccleaner-installs-ghostdesk-chrome-spyware\" target=\"_blank\" rel=\"noopener\">post<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Alongside GhostDesk, the researchers also identified fake 7-zip and Adobe Acrobat applications using the same techniques and command-and-control (C2) infrastructure.<\/p>\n<p class=\"wp-block-paragraph\">CCleaner is a popular Windows PC cleaner <a href=\"https:\/\/www.ccleaner.com\/ccleaner\/download?srsltid=AfmBOoqFWtpR8d9AueS7Z9YLHF3ZQfXMcJEs6EFT_E1cgyCfEgSgt4Xy\">utility<\/a>, with more than 2 billion downloads worldwide. Wheeler said \u201cthe executable (fake CCleaner) initially drops a legitimate instance of CScript, then uses it to launch a series of (malicious) scripts.\u201d<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>A fake cleaner with a multi-stage payload<\/h2>\n<p class=\"wp-block-paragraph\">The attack begins when a victim downloads the fake CCleaner executable file from the impersonated site \u201cccleanerwind[.]top.\u201d Malwarebytes found that both the site\u2019s regular and \u201cCleaner Pro\u201d download buttons delivered the same malicious file.<\/p>\n<p class=\"wp-block-paragraph\">When executed, \u201ccscript.exe\u201d runs a series of scripts carrying out basic system reconnaissance like collecting the machine GUID, hostname, and supported languages. It then replaces \u201cruntimebroker.dll\u201d in the user\u2019s AppData directory with a reflexive loader and modifies Chrome\u2019s Security Extension manifest.<\/p>\n<p class=\"wp-block-paragraph\">This modification allows the attacker to inject two JavaScript files, \u201cbackground.js\u201d and \u201ccontent.js,\u201d that run as a malicious extension whenever Chrome starts. The resulting malware Malwarebytes tracks as GhostDesk.<\/p>\n<p class=\"wp-block-paragraph\">While content.js was seen recording keystrokes and scanning submitted forms for credentials, authentication tokens, and financial information, background.js provided cookie theft, screenshot capture, and arbitrary <a href=\"https:\/\/www.csoonline.com\/article\/4168568\/13-new-critical-holes-in-javascript-sandbox-allow-execution-of-arbitrary-code.html\">JavaScript<\/a> execution.<\/p>\n<p class=\"wp-block-paragraph\">content.js was also found capable of monitoring clipboard activity and replacing cryptocurrency addresses when victims paste them into websites.<\/p>\n<p class=\"wp-block-paragraph\">background.js provides persistence as it communicates through a WebSocket relay and can re-establish that connection when Chrome starts, Wheeler pointed out.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>The campaign is bigger than GhostDesk<\/h2>\n<p class=\"wp-block-paragraph\">The campaign\u2019s impact was traced beyond users who specifically searched for CCleaner. Malwarebytes found fake 7-zip and Adobe Acrobat samples using the same CScript loading mechanism, with the samples communicating with the same C2 at \u201cliderongrade.duckdns[.]org.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The only difference observed was some Adobe samples using \u201cwscript.exe\u201d instead of cscript.exe, likely attackers attempting to adapt delivery to different software, Wheeler noted.<\/p>\n<p class=\"wp-block-paragraph\">The combination of browser cookies, credentials, keystrokes and screen captures <a href=\"https:\/\/www.csoonline.com\/article\/4198788\/new-acr-stealer-campaigns-use-webdav-mshta-to-evade-detection.html\">makes<\/a> the compromise concerning for enterprises and worth setting protections against. Captured authentication tokens and financial information add further risk.<\/p>\n<p class=\"wp-block-paragraph\">Malwarebytes recommended checking the web address carefully before downloading software, noting that sponsored search results can be abused by cybercriminals. It also advised treating software download links shared through social media, SMS and email with caution, and verifying downloads against trusted sources such as the publisher\u2019s official website or app stores.<\/p>\n<p class=\"wp-block-paragraph\">The company also recommended using an up-to-date, real-time anti-malware solution with web protection. The one from Malwarebytes blocks connections to unsafe sites such as the fake CCleaner landing page and detects the fake installer as \u201cTrojan.Dropper,\u201d it added.<\/p>\n<p class=\"wp-block-paragraph\">Keeping the operating system, browser, and security software up to date remains a must.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A convincing fake version of the widely used CCleaner utility is being used to deliver a multi-stage Windows malware that ultimately abuses Google Chrome for credential theft and surveillance. Researchers from Malwarebytes found the campaign distributing a malicious Chrome extension called GhostDesk, which can capture credentials, cookies, keystrokes, and screenshots while also allowing attackers to [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9114,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9113","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9113"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9113"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9113\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9114"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9113"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9113"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9113"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}