Threat Advisory

CCleaner Fake App Installs Malicious Chrome Extension

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A fake version of the popular PC cleaning tool CCleaner is being used to infect Windows users with a malicious Chrome extension called GhostDesk, which acts as spyware inside the browser. The attack starts on a convincing imitation of the CCleaner download page, where victims install a fake application that modifies Chrome, installs malicious extension components, and gives attackers the ability to steal credentials, capture screenshots, and log keystrokes. The malware uses CScript to launch a multi-stage infection, patches Chrome’s Security Extension, establishes a command-and-control (C2) channel, and ultimately installs GhostDesk.

The initial infection vector is a fake a malicious executable on a website designed to imitate the official home page. The executable initially drops a legitimate instance of CScript, then uses it to launch scripts that do system reconnaissance, hijack Runtime Broker, patch Chrome Security Extension, and establish a C2 connection. These scripts create local WebSocket endpoints, upgrade them to connect to the public domain/port :4444, and send regular keep-alive packets from the attacker’s server. The second stage involves malicious Chrome extension components that perform keylogging, form-based credential harvesting, cryptojacking, script injection, and cookie theft.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A fake version of the popular PC cleaning tool CCleaner is being used to infect Windows users with a malicious Chrome extension called GhostDesk, which acts as spyware inside the browser. The attack starts on a convincing imitation of the CCleaner download page, where victims install a fake application that modifies Chrome, installs malicious extension components, and gives attackers the ability to steal credentials, capture screenshots, and log keystrokes. The malware uses CScript to launch a multi-stage infection, patches Chrome’s Security Extension, establishes a command-and-control (C2) channel, and ultimately installs GhostDesk.

The initial infection vector is a fake a malicious executable on a website designed to imitate the official home page. The executable initially drops a legitimate instance of CScript, then uses it to launch scripts that do system reconnaissance, hijack Runtime Broker, patch Chrome Security Extension, and establish a C2 connection. These scripts create local WebSocket endpoints, upgrade them to connect to the public domain/port :4444, and send regular keep-alive packets from the attacker’s server. The second stage involves malicious Chrome extension components that perform keylogging, form-based credential harvesting, cryptojacking, script injection, and cookie theft.[emaillocker id="1283"]

This campaign takes advantage of the reputation of a popular app by distributing malware through a convincing lookalike website. A professional-looking download page isn’t enough to prove a site is legitimate. The threat has been identified in multiple fake apps with identical behavior, connecting to the same C2 server. To stay safe, carefully check web addresses before downloading software and use an up-to-date anti-malware solution with web protection.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Execution T1059.003 Command and Scripting Interpreter Windows Command Shell
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1036.005 Masquerading Match Legitimate Resource Name or Location
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

MBC MAPPING:

Objective Behavior ID Behavior
Command & Control B0030 C2 Communication
Persistence F0012 Registry Run Keys / Startup Folder
Execution E1204 User Execution
Discovery E1083 File and Directory Discovery
Anti-Static Analysis E1027 Obfuscated Files or Information
Command & Control E1105 Ingress Tool Transfer
Defense Evasion B0029 Polymorphic Code

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu