CCleaner Backdoor
Aliases: DIRTCLEANER
- First seen
- 2017-09-18 00:00:00
- Malware type
- backdoor, trojan
- Last IoC activity
- 2026-07-18 23:59:03
- Profile updated
- 2026-07-07 12:56:59
Targeted industries: technology-and-telecommunications financial-services healthcare-and-pharmaceutical government-and-public-sector
Context
According to CrowdStrike, this backdoor was discovered embedded in the legitimate, signed version of CCleaner 5.33, and thus constitutes a supply chain attack.
Reports & references
- secureworks.com — Bronze Atlas (report)
- Kaspersky — 97239 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Ccleaner Backdoor (report)
- CrowdStrike — Protecting Software Supply Chain Deep Insights Ccleaner Backdoor (report)
- Mandiant — Pe File Infecting Malware Ot (report)
- blog.avast.com — Additional Information Regarding The Recent Ccleaner Apt Security Incident (report)
- risky.biz — Whatiswinnti (report)
- twitter.com — 910148928796061696 (report)
- ptsecurity.com — Winnti 2020 Eng (report)
- blog.avast.com — New Investigations In Ccleaner Incident Point To A Possible Third Stage That Had Keylogger Capacities (report)
- ptsecurity.com — Winnti 2020 Rus (report)
- Cisco Talos — Ccleaner C2 Concern (report)
- wired.com — Ccleaner Malware Targeted Tech Firms (report)
- securityintelligence.com — Security Utility Abuses Supply Chain For A Malware Attack (report)
- blog.morphisec.com — Morphisec Discovers Ccleaner Backdoor (report)
- intezer.com — Evidence Aurora Operation Still Active Part 2 More Ties Uncovered Between Ccleaner Hack Chinese Hackers (report)
- Cisco Talos — Avast Distributes Malware (report)
- CrowdStrike — In Depth Analysis Of The Ccleaner Backdoor Stage 2 Dropper And Its Payload (report)
- stmxcsr.com — Print Processor (report)
- blog.avast.com — Update Ccleaner Attackers Entered Via Teamviewer (report)
- blog.avast.com — Avast Threat Labs Analysis Of Ccleaner Incident (report)
- blog.avast.com — Progress On Ccleaner Investigation (report)
- intezer.com — Evidence Aurora Operation Still Active Supply Chain Attack Through Ccleaner (report)