Proprietary · · 185 days

CCleaner installer shipped multi-stage backdoor

Attackers compromised Piriform's build environment and inserted a backdoor into official CCleaner releases before Avast completed the acquisition.

The CCleaner compromise began before the public software update. Avast later found that attackers first entered Piriform's network on March 11, 2017, using TeamViewer on an unattended developer workstation. The single successful sign-in suggested the attacker already had valid credentials. Initial DLL drops failed without admin rights; the third attempt used VBScript and succeeded.

On March 12, the actor moved to a second unattended computer and opened a backdoor through Windows Remote Desktop. In April, a customized ShadowPad payload appeared inside Piriform as mscoree.dll, including on a build server. Avast found no proof that this ShadowPad stage was later delivered to the 40 selected CCleaner victims, but it showed the attacker had months of internal access before the customer-facing payload shipped.

The delivery was the official CCleaner installer. On August 2, attackers replaced the normal build path with a backdoored CCleaner release, and version 5.33.6162 was later downloaded by roughly 2.27 million users. The first stage collected system information and contacted command-and-control, acting less like broad ransomware and more like a filter for targets worth a second step.

The second stage went to 40 computers at major technology and telecommunications companies. Cisco Talos detected the malicious official download on September 13 and notified Avast; with FBI help, Avast took down the command-and-control server within three days. The lasting lesson was bleak and simple: a free utility with a trusted update path can become an intelligence platform if its build chain is owned.

Appendix · Affected releases

CCleaner windows installer
5.33.6162 sha256 1a4a5123…cf6030ff download unavailable
CCleaner Cloud windows installer
1.07.3191 no sample yet
  • No digest for this build appears in any retained source, searched 2026-09-02. Talos, eSentire, VulnCheck and Piriform's own notification publish the same three SHA-256s in one block, all attributed here to the 5.33.6162 side.
  • MalwareBazaar's Floxif corpus was searched too. Its one CCleaner-shaped candidate, CCSetup.exe 99d9b3e4..., is an InstallShield package with no Piriform string, where CCleaner shipped NSIS, so it was rejected.
  • This is a research gap in the public reporting rather than an artifact no archive will serve, and it stays unresolved until a source names a digest for the Cloud build specifically.
  • Second-stage DLL deployed only to selected high-value targets after the first-stage CCleaner compromise.
  • Avast reported 40 selected second-stage victims at major technology and telecommunications companies.

Indicators

  • observableTeamViewer access to Piriform developer workstation
  • observableWindows Remote Desktop lateral movement
  • filemscoree.dll
  • observableShadowPad found on Piriform build infrastructure

References

  1. CCleaner incident report - now and thenblog.avast.com
  2. Recent findings from CCleaner APT investigation reveal that attackers entered the Piriform network via TeamViewerblog.avast.com
  3. CCleaner Command and Control Causes Concernblogs.cisco.com
  4. Talos Intelligence: CCleaner Command and Controltalosintelligence.com
  5. CCleaner Attack Timeline - Here's How Hackers Infected 2.3 Million PCsthehackernews.com

Source record: proprietary/ccleaner/meta.yaml