Rantburg

Today's Front Page   View All of Thu 05/29/2025 View Wed 05/28/2025 View Tue 05/27/2025 View Mon 05/26/2025 View Sun 05/25/2025 View Sat 05/24/2025 View Fri 05/23/2025
2017-09-18 -Short Attention Span Theater-
Hackers Hid Backdoor In CCleaner Security App With 2 Billion Downloads -- 2.3 Million Infected
Users of Avast-owned security application CCleaner for Windows have been advised to update their software immediately, after researchers discovered criminal hackers had installed a backdoor in the tool. The tainted application allows for download of further malware, be it ransomware or keyloggers, with fears millions are affected. According to Avast's own figures, 2.27 million ran the affected software, though the company said users should not panic.

The affected app, CCleaner, is a maintenance and file clean-up software run by a subsidiary of anti-virus giant Avast. It has 2 billion downloads and claims to be getting 5 million extra a week, making the threat particularly severe, researchers at Cisco Talos warned. Comparing it to the NotPetya ransomware outbreak, which spread after a Ukrainian accounting app was infected, the researchers discovered the threat on September 13 after CCleaner 5.33 caused Talos systems to flag malicious activity.

Further investigation found the CCleaner download server was hosting the backdoored app as far back as September 11. Talos warned in a blog Monday that the affected version was released on August 15, but on September 12 an untainted version 5.34 was released. For weeks then, the malware was spreading inside supposedly-legitimate security software.

The malware would send encrypted information about the infected computer - the name of the computer, installed software and running processes - back to the hackers' server. The hackers also used what's known as a domain generation algorithm (DGA); whenever the crooks' server went down, the DGA could create new domains to receive and send stolen data. Use of DGAs shows some sophistication on the part of the attackers.

CCleaner's owner, Avast-owned Piriform, has sought to ease concerns. Paul Yung, vice president of product at Piriform, wrote in a post Monday: "Based on further analysis, we found that the 5.33.6162 version of CCleaner and the 1.07.3191 version of CCleaner Cloud was illegally modified before it was released to the public, and we started an investigation process.
Posted by gorb 2017-09-18 06:35|| || Front Page|| [11129 views ]  Top

#1 Headquartered in Praque, Czech Republic.

US has just advised not to use Kaspersky anit-virus either. Headquarted in Moscow, Russia.

Globalist entities. Players in the fall of 'Rome'.
Posted by Hupeting Sforza8196 2017-09-18 07:19||   2017-09-18 07:19|| Front Page Top

#2 I guess I'm OK. Haven't updated from V4.16. Sometimes it pays to let others test the water.
Posted by ed in texas 2017-09-18 07:55||   2017-09-18 07:55|| Front Page Top

#3 I installed v. 5.34.6207 last week. That's the version you should upgrade to if you're running CCleaner.
Posted by Raj 2017-09-18 11:21||   2017-09-18 11:21|| Front Page Top

#4 One word "LINUX".
Posted by 3dc 2017-09-18 12:02||   2017-09-18 12:02|| Front Page Top

#5 Sometimes you get more than what you pay for.
Posted by Skidmark 2017-09-18 18:02||   2017-09-18 18:02|| Front Page Top

#6  Sometimes you get more than what you pay for.

And "free" is often priced appropriately, tho I have found CCleaner useful with adult supervision.
Posted by M. Murcek 2017-09-18 18:46||   2017-09-18 18:46|| Front Page Top

14:04 swksvolFF
13:47 Regular joe
13:43 swksvolFF
13:38 swksvolFF
13:34 swksvolFF
13:31 Abu Uluque
13:25 Heribertus Vedente
13:24 mossomo
13:20 Abu Uluque
13:14 mossomo
13:06 swksvolFF
12:51 Grom the Affective
12:31 Abu Uluque
12:20 swksvolFF
12:17 Abu Uluque
12:08 swksvolFF
12:08 ed in texas
12:05 ed in texas
12:01 ed in texas
12:00 ed in texas
11:58 ed in texas
11:56 ed in texas
11:55 Grom the Affective
11:53 Grom the Affective









Paypal:
Google
Search WWW Search rantburg.com