CCleaner,France Archives a popular Windows app for system optimization and maintenance, has at some point been hijacked by hackers, potentially tricking millions of people into installing malware on their personal computers.
The threat was discovered by security researchers at Cisco Talos, who noticed that CCleaner was triggering their malware protection systems on Sept. 13. After looking into the problem, they realized that CCleaner version 5.33 came together with dangerous malware.
To make matters worse, we're not talking about downloading the app on some shady third-party site. Users who downloaded CCleaner directly from the official site, as recently as Sept. 11, were in fact downloading the infected version of the software.
SEE ALSO: Beware, Google Play Store gets caught distributing malwareAccording to Cisco Talos, only version 5.33 of the software is affected, and the more recent 5.34 version of CCleaner is malware-free. The malware doesn't do much damage by itself, but opens up the possibility for hackers to remotely install other malware, with potentially devastating consequences.
This was confirmed by the app's maker, Piriform, which was acquired by anti-virus software maker Avast in July. In a blog post, the company's VP of Products Paul Yung said that another one of it software products, CCleaner Cloud (version 1.07.3191), has also been affected.
These two apps were "illegally modified before (they were) released to the public," the post said. "The threat has now been resolved in the sense that the rogue server is down, other potential servers are out of the control of the attacker and we’re moving all existing CCleaner v5.33.6162 users to the latest version. Users of CCleaner Cloud version 1.07.3191 have received an automatic update."
UPDATE: Sept. 19, 2017, 9:31 a.m. UTC According to Piriform, only 32-bit versions of the software are affected.
It's currently unknown who's behind the hack, or how they managed to sneak malware into official CCleaner installs. "At this stage, we don’t want to speculate how the unauthorized code appeared in the CCleaner software, where the attack originated from, how long it was being prepared and who stood behind it," Yung said.
The CCleaner app is very popular -- Piriform claimed 2 billion CCleaner downloads and 5 million desktop installs weekly as of Nov. 2016. The infected version of the software was released on Aug. 15, meaning that millions of users are potentially at risk.
While Piriform claims that it was "able to disarm the threat before it was able to do any harm," it's unclear whether this is really the case. Users who'd had undetected malware on their computers for (potentially) a month could've had their data stolen or their systems compromised in other ways.
Unfortunately, there's very little users could've done to prevent this from happening, as the malware came with an official app, hosted on an official server. Everyone who installed CCleaner in the period from August 15 until now should update to the newest version of the software and run an anti-malware scan.
Topics Cybersecurity
Previous:Preserve Yourself!
Next:A Rich Fable
This is far and away the mostTesla's autonomous trucks will move in platoons, report saysYou are finally free from the first embarrassing song on your phoneI know, I know ... I'm using Instagram all wrong and I don't care'Own the School Year Like a Hero' sign displayed above Walmart gun rackNintendo's detachable controller design draws accusations of patent infringementTattooist creates mesmerising flipbookYou are finally free from the first embarrassing song on your phoneThis guy missed his high school so much he recreated it on MinecraftElon Musk says story about fired assistant is 'total nonsense'Hundreds of frozen pizzas left on highway after truck crashesYou are finally free from the first embarrassing song on your phone'Call of Duty' figures out how to make loot boxes even more awful'Game of Thrones' Season 7, episode 5 photos: 'Eastwatch'Facebook cracks down on sketchy bait and switch adsMiami Heat become first NBA team with mobileHBO offered hackers a 'bounty payment' of $250,000 last monthSorry, but you're doing your pa$$w0rds all wrongCongrats world, you watched Snapchat's dancing hot dog 1.5 billion times'Game of Thrones' recasting: 11 characters who switched roles Samsung Galaxy Note 10: Everything we know about the phone so far Bradley Whitford on being the newest 'Handmaid's Tale' baddie Huawei cancels laptop launch because of U.S. ban The biggest trailers and news from Ubisoft's E3 2019 press conference Scary deepfake tool lets you put words into someone's mouth Fifth Harmony's Lauren Jauregui arrested for possession of marijuana Young WNBA fan sobs with excitement over post Chernobyl is now an Instagram hot spot thanks to the HBO show Donald Trump and Peter Thiel have a secret handshake, I guess United Nations drops Wonder Woman as honorary ambassador Queen Cersei strikes down Donald Trump with 1 thunderous tweet Jill Stein wants moral high ground after cashing in on Trump fear 'Big Little Lies' Season 2 is back to make Wife Guys of us all Nintendo at E3 2019: An interview with Doug Bowser 'Russian Doll' renewed for second season at Netflix Tinder on TV is your new favourite party game Gwyneth Paltrow forgot she was in 'Spider 'Psychonauts 2's E3 demo gets you in the funnies and in the feels Uber Eats will test food drone delivery in San Diego Summer 2019 Apple's new Mac Pro may be coming in September
2.1389s , 8222.9453125 kb
Copyright © 2025 Powered by 【France Archives】,Charm Information Network