PCWorld (USA)

Ccleaner hacked with malware: What you need to know

More than 2 million users possibly at risk.

- BY MICHAEL SIMON

It seems that Ccleaner, one of Pcworld’s recommenda­tions for the best free software for new PCS ( go. pcworld.com/fspc), might not have been keeping your PC so clean after all. In an in-depth probe of the popular optimizati­on and scrubbing software, Cisco Talos ( go. pcworld.com/ssct) has discovered a malicious bit of code injected by hackers that could have affected more than 2 million users who downloaded the most recent update.

On Sept. 13, Cisco Talos found that the official download of the free versions of Ccleaner 5.33 and Ccleaner Cloud 1.07.3191 also contained “a malicious payload that featured a Domain Generation

Algorithm as well as hardcoded Command and Control functional­ity.” What that means is that a hacker infiltrate­d Avast Piriform’s official build somewhere in the developmen­t process build to plant malware designed to steal users’ data.

Cisco Talos suspects that the attacker “compromise­d a portion of (Ccleaner’s) developmen­t or build environmen­t and leveraged that access to insert malware into the Ccleaner build that was released and hosted by the organizati­on.” As such, customers’ personal informatio­n was not at risk.

In a blog post ( go.pcworld.com/iabp) by vice president of products Paul Yung, he states that the company identified the attack on Sept. 12 and had taken the appropriat­e action even before Cisco Talos notified them of their discovery. Yung says the attack was limited to Ccleaner and Ccleaner Cloud on 32-bit Windows systems—fortunatel­y, most modern PCS will likely be running the 64-bit version.

Yung assures customers that the threat has been resolved and the “rogue server” has been taken down. He also says Piriform has shut down the hackers’ access to other servers. Additional­ly, the company is moving all users to the latest version of the software, which is already available on the company’s website (though the release notes ( go.pcworld.com/ttrn) only mention “minor big fixes.”)

On September 21, Avast ( go.pcworld. com/s21a) revealed that the malware was designed to deliver a second-stage payload to infected computers in specific organizati­ons, and at least 20 machines across eight companies contacted the command and control server. “Given that the logs were only collected for little over three days, the actual number of computers that received the 2nd stage payload was likely at least in the order of hundreds,” Avast says.

Cisco Talos ( go.pcworld.com/ctas) also studied the malware’s command server and reports that it was attempting to infiltrate

PCS in technology organizati­ons, including Intel, Samsung, HTC, Vmware, Cisco itself, and others. You can see the full list

below. Cisco Talos suspects the attackers planned to use the malware to conduct industrial espionage.

WHAT TO DO ABOUT CCLEANER MALWARE

Personal users can download Ccleaner 5.34 ( go.pcworld.com/pucd) from Avast’s website if they haven’t already done so. Previous releases are also still available on the company’s website, but the infected version has been removed from the company’s servers. You’ll also want to perform an antivirus scan ( go.pcworld.com/paas) on your computer. If you’re affected, Cisco Talos recommends using a backup ( go.pcworld. com/ruab) to restore your PC to a state prior to August 15, 2017, which is when the hacked version was released.

The impact on you at home: While personal users within the target area shouldn’t see any impact from this attempted attack, it’s still a scary notion. While Avast got in front of the issue and resolved it without incident, smaller companies might not be able to react so quickly. For example, earlier this year, it was found that a breach at Ukranian software company Medoc was responsibl­e for the Notpetya ( go.pcworld.com/mdwr) ransomware. Ransomware is becoming a troubling trend, and if hackers are able to infect infect update servers they can spread malware to as many machines as possible.

 ??  ??
 ??  ??
 ??  ??

Newspapers in English

Newspapers from Australia