CCleaner Compromised by Hackers, Potentially Giving Access to Over 2 Million Devices: Avast

Advertisement
By Reuters | Updated: 21 September 2017 10:23 IST
CCleaner Compromised by Hackers, Potentially Giving Access to Over 2 Million Devices: Avast

Hackers broke into British company Piriform's free software for optimising computer performance last month potentially allowing them to control the devices of more than two million users, the company and independent researchers said on Monday.

The malicious program was slipped into legitimate software called CCleaner, which is downloaded for personal computers and Android phones as often as five million times a week. It cleans up junk programs and advertising cookies to speed up devices.

CCleaner is the main product made by London's Piriform, which was bought in July by Prague-based Avast, one of the world's largest computer security vendors. At the time of the acquisition, the company said 130 million people used CCleaner.

A version of CCleaner downloaded in August included remote administration tools that tried to connect to several unregistered web pages, presumably to download additional unauthorised programs, security researchers at Cisco's Talos unit said.

Advertisement

Talos researcher Craig Williams said it was a sophisticated attack because it penetrated an established and trusted supplier in a manner similar to June's "NotPetya" attack on companies that downloaded infected Ukrainian accounting software.

"There is nothing a user could have noticed," Williams said, noting that the optimisation software had a proper digital certificate, which means that other computers automatically trust the program.

Advertisement

In a blog post, Piriform confirmed that two programs released in August were compromised. It advised users of CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 to download new versions. A spokeswoman said that 2.27 million users had downloaded the August version of CCleaner while only 5,000 users had installed the compromised version of CCleaner Cloud.

Piriform said that Avast, its new parent company, had uncovered the attacks on September 12. A new, uncompromised version of CCleaner was released the same day and a clean version of CCleaner Cloud was released on Sept. 15, it said.

Advertisement

The nature of the attack code suggests that the hacker won access to a machine used to create CCleaner, Williams said.

CCleaner does not update automatically, so each person who has installed the problematic version will need to delete it and install a fresh version, he said.

Williams said that Talos detected the issue at an early stage, when the hackers appeared to be collecting information from infected machines, rather than forcing them to install new programs.

Piriform said it had worked with US law enforcement to shut down a server located in the United States to which traffic was set to be directed.

It said the server was closed down on September 15 "before any known harm was done".

© Thomson Reuters 2017

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: CCleaner, Internet, Apps, Hacking, Android
Advertisement

Related Stories

Popular Mobile Brands
  1. iQOO Z10 Lite 5G With 6,000mAh Battery Launched in India: Price, Features
  2. Vivo X200 FE Launch Date, Colours, and Design Revealed Ahead of Launch
  3. Redmi Pad 2 With 11-Inch 2.5K Display, 9,000mAh Battery Launched in India
  4. Oppo Reno 14 5G, Reno 14 Pro 5G India Launch Timeline Leaked
  5. Nothing Headphone 1 Price, Colour Options Leaked Ahead of Launch
  6. Apple Back to School Offer Brings Discounts on iPad Air, Other Products
  7. Pixel 10, Pixel 10 Pro Alleged Case Hint at Design Changes
  8. Google Pixel 10 Series Said to Get Faster Ultrasonic Fingerprint Sensor
  9. Vivo T4 Ultra Now Available for Purchase in India: See Price, Offers
  1. Warner Bros. Games Restructures to Focus on Harry Potter, Game of Thrones, Mortal Kombat and DC Franchises
  2. Google Pixel 10, Pixel 10 Pro Alleged Case Suggests Minor Design Changes From Predecessors
  3. Oppo Reno 14 5G, Reno 14 Pro 5G India Launch Timeline Leaked
  4. Nothing Phone 3 to Offer Longer Android and Security Update Support Than Its Predecessor
  5. Boat Wave Fortune Smartwatch With NFC Tap & Pay Feature, Bluetooth Calling Launched in India
  6. Government Announces FASTag-Based Annual Pass for Highway Commutes Priced at Rs. 3,000: See Benefits
  7. Adobe Firefly App for Android and iOS Announced, Offers AI-Powered Image and Video Tools
  8. Axiom-4 Mission Carrying Shubhanshu Shukla to International Space Station Postponed to June 22
  9. Bungie Delays Marathon, Says Will Reveal New Release Date This Fall
  10. Vivo T4 Ultra Now Available for Purchase in India: See Price, Offers, Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.