CCleaner,OKASANNOANARU-02 a popular Windows app for system optimization and maintenance, has at some point been hijacked by hackers, potentially tricking millions of people into installing malware on their personal computers.
The threat was discovered by security researchers at Cisco Talos, who noticed that CCleaner was triggering their malware protection systems on Sept. 13. After looking into the problem, they realized that CCleaner version 5.33 came together with dangerous malware.
To make matters worse, we're not talking about downloading the app on some shady third-party site. Users who downloaded CCleaner directly from the official site, as recently as Sept. 11, were in fact downloading the infected version of the software.
SEE ALSO: Beware, Google Play Store gets caught distributing malwareAccording to Cisco Talos, only version 5.33 of the software is affected, and the more recent 5.34 version of CCleaner is malware-free. The malware doesn't do much damage by itself, but opens up the possibility for hackers to remotely install other malware, with potentially devastating consequences.
This was confirmed by the app's maker, Piriform, which was acquired by anti-virus software maker Avast in July. In a blog post, the company's VP of Products Paul Yung said that another one of it software products, CCleaner Cloud (version 1.07.3191), has also been affected.
These two apps were "illegally modified before (they were) released to the public," the post said. "The threat has now been resolved in the sense that the rogue server is down, other potential servers are out of the control of the attacker and we’re moving all existing CCleaner v5.33.6162 users to the latest version. Users of CCleaner Cloud version 1.07.3191 have received an automatic update."
UPDATE: Sept. 19, 2017, 9:31 a.m. UTC According to Piriform, only 32-bit versions of the software are affected.
It's currently unknown who's behind the hack, or how they managed to sneak malware into official CCleaner installs. "At this stage, we don’t want to speculate how the unauthorized code appeared in the CCleaner software, where the attack originated from, how long it was being prepared and who stood behind it," Yung said.
The CCleaner app is very popular -- Piriform claimed 2 billion CCleaner downloads and 5 million desktop installs weekly as of Nov. 2016. The infected version of the software was released on Aug. 15, meaning that millions of users are potentially at risk.
While Piriform claims that it was "able to disarm the threat before it was able to do any harm," it's unclear whether this is really the case. Users who'd had undetected malware on their computers for (potentially) a month could've had their data stolen or their systems compromised in other ways.
Unfortunately, there's very little users could've done to prevent this from happening, as the malware came with an official app, hosted on an official server. Everyone who installed CCleaner in the period from August 15 until now should update to the newest version of the software and run an anti-malware scan.
Topics Cybersecurity
China’s Geely steps up restructuring with new intelligent driving brand · TechNodeByteDance launches Trae AI IDE in China with DoubaoXpeng Motors prepares for ADAS available outside of China: CEO · TechNodeManus partners with Alibaba’s Qwen to expand AI capabilities · TechNodeMoon photo reveals how lunar landing just went wrongHuawei applies for trademarks on the Monkey King and other fictional figures · TechNodeAT&T data breach impacts tens of millions of customersMysterious U.S. spaceplane returns to Earth, and Space Force snaps photosSamsung Galaxy Watch Ultra handsTongji University purchases 10 Unitree humanoid robots for student training · TechNodeFormer Intel directors oppose TSMC’s takeover of Intel’s foundry · TechNodeTencent’s Yuanbao tops Apple’s China App Store, surpassing DeepSeek · TechNodeChinese expert predicts smallmiHoYo founder’s AI game Whispers From The Star features realFree Slurpee Day 2024: How to get one and why it mattersDidi’s selfManus partners with Alibaba’s Qwen to expand AI capabilities · TechNodeByteDance dismisses hundreds of employees for corruption · TechNodeShop early Prime Day iPad dealsGoogle partners with MediaTek for next Some genius used a piece of dried pasta to improve his joint 15 protests that defined 2020 Tinder Gold drives app to number one grossing spot on the App Store Here's how much the ideal Apple Fitness+ setup will cost you An emotional Miley Cyrus tries to explain why she's donating to Hurricane Harvey relief Humanity dumped 37 billion tons of CO2 into the atmosphere in 2020 Hyundai acquires robotics company Boston Dynamics in $1.1 billion deal Taylor Swift’s ‘evermore’ review: A thoughtful note for a dark year This activist is a beacon of hope for reproductive justice in the South Republicans and Democrats actually agree on breaking up Facebook Santa Claus can give you directions in Waze these holidays Walmart is selling cheap knockoff versions of Donald Trump's USA hat 12 kids who don't care what you think Instagram and Facebook users report messaging issues Just 23 great photos of cats standing on two legs 'New Girl' was a fun show with an anticlimactic ending Perfect photobomb turns lady into a beautiful butterfly HBO's 'Avenue 5' is the perfect companion to this crapfest of a year Hotel has an incredibly strange offer for lonely customers 'Big Mouth' made a great point with its 'Pen15' crossover
2.4989s , 8225.796875 kb
Copyright © 2025 Powered by 【OKASANNOANARU-02】,Unobstructed Information Network