CCBkdr
MITRE ATT&CK: S0222 View on attack.mitre.org
Aliases: CCBkdr
- First seen
- 2017-09-12 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 14:52:01
Targeted industries: technology-and-telecommunications
Context
CCBkdr is malware that was injected into a signed version of CCleaner and distributed from CCleaner's distribution website.
Detection coverage
- 5 Sigma rules
Malware & tools used
- Compromise Software Supply Chain (attack-pattern)
- Domain Generation Algorithms (attack-pattern)
Reports & references
- Cisco Talos — Avast Distributes Malware (report)
- intezer.com — Evidence Aurora Operation Still Active Supply Chain Attack Through Ccleaner (report)
- MITRE ATT&CK — S0222 (report)