A fake version of the popular PC cleaning tool CCleaner is being used to infect Windows users with a malicious Chrome extension called GhostDesk, which acts as spyware inside the browser. The attack starts on a convincing imitation of the CCleaner download page, where victims install a fake application that modifies Chrome, installs malicious extension components, and gives attackers the ability to steal credentials, capture screenshots, and log keystrokes. The malware uses CScript to launch a multi-stage infection, patches Chrome’s Security Extension, establishes a command-and-control (C2) channel, and ultimately installs GhostDesk.
The initial infection vector is a fake a malicious executable on a website designed to imitate the official home page. The executable initially drops a legitimate instance of CScript, then uses it to launch scripts that do system reconnaissance, hijack Runtime Broker, patch Chrome Security Extension, and establish a C2 connection. These scripts create local WebSocket endpoints, upgrade them to connect to the public domain/port :4444, and send regular keep-alive packets from the attacker’s server. The second stage involves malicious Chrome extension components that perform keylogging, form-based credential harvesting, cryptojacking, script injection, and cookie theft.[/subscribe_to_unlock_form]
A fake version of the popular PC cleaning tool CCleaner is being used to infect Windows users with a malicious Chrome extension called GhostDesk, which acts as spyware inside the browser. The attack starts on a convincing imitation of the CCleaner download page, where victims install a fake application that modifies Chrome, installs malicious extension components, and gives attackers the ability to steal credentials, capture screenshots, and log keystrokes. The malware uses CScript to launch a multi-stage infection, patches Chrome’s Security Extension, establishes a command-and-control (C2) channel, and ultimately installs GhostDesk.
The initial infection vector is a fake a malicious executable on a website designed to imitate the official home page. The executable initially drops a legitimate instance of CScript, then uses it to launch scripts that do system reconnaissance, hijack Runtime Broker, patch Chrome Security Extension, and establish a C2 connection. These scripts create local WebSocket endpoints, upgrade them to connect to the public domain/port :4444, and send regular keep-alive packets from the attacker’s server. The second stage involves malicious Chrome extension components that perform keylogging, form-based credential harvesting, cryptojacking, script injection, and cookie theft.[emaillocker id="1283"]
This campaign takes advantage of the reputation of a popular app by distributing malware through a convincing lookalike website. A professional-looking download page isn’t enough to prove a site is legitimate. The threat has been identified in multiple fake apps with identical behavior, connecting to the same C2 server. To stay safe, carefully check web addresses before downloading software and use an up-to-date anti-malware solution with web protection.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.003 | Command and Scripting Interpreter | Windows Command Shell |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Command & Control | B0030 | C2 Communication |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
| Execution | E1204 | User Execution |
| Discovery | E1083 | File and Directory Discovery |
| Anti-Static Analysis | E1027 | Obfuscated Files or Information |
| Command & Control | E1105 | Ingress Tool Transfer |
| Defense Evasion | B0029 | Polymorphic Code |
The following reports contain further technical details:
[/emaillocker]