September 19, 2017 By Larry Loeb 2 min read

Over 2 million users have installed infected versions of a security application owned by software firm Avast.

According to Cisco Talos, CCleaner version 5.33, which was available as a legitimate download from Aug. 15 to Sept. 12, was found to contain a multistage malware attack hidden inside of it. CCleaner Cloud v1.07.3191 was also infected by the malware.

Characteristics of the Malware Attack

Floxif is a downloader that gathers information about infected systems and then sends it back to the command-and-control (C&C) server associated with it, reported Bleeping Computer. The malware gleans the computer name, a list of software installed, a list of running processes, MAC addresses for the first three network interfaces and unique IDs that identify each computer. It only runs on 32-bit systems, which have to be administrator accounts.

If the primary C&C server does not return a response to the HTTP POST request made by the malware, it uses a domain generation algorithm (DGA) to generate a new location. The DGA is time-based and can be calculated using the values of year and month. Cisco evaluated the DGA and sinkholed the domains it produced to prevent them from being used in an attack.

Floxif can run other binaries, but there is not yet any evidence that another payload was downloaded and run on the infected systems.

Supply Chain Problem

Cisco Talos believed that the threat actors compromised Avast’s supply chain. Avast bought Piriform, the utility’s actual developer, in July, which was one month before the poisoned version made its appearance. Piriform confirmed the problem in a blog post.

Since the malware binary was digitally signed using a valid certificate issued to the software developer, the attacker was able to breach somewhere in the development process and switch out the production version for the malware version. It’s possible that the change in company ownership facilitated this supply chain attack.

“2.27 million is certainly a large number, so we’re not downplaying in any way,” Avast chief technology officer (CTO) Ondrej Vlcek told Forbes. “It’s a serious incident. But based on all the knowledge, we don’t think there’s any reason for users to panic.”

While the cloud-based version of CCleaner will accept an update pushed out by Avast, the app version will not. Anyone who downloaded the antivirus software during the infection period must update the app manually to undo this infection.

More from

What does resilience in the cyber world look like in 2025 and beyond?

6 min read -  Back in 2021, we ran a series called “A Journey in Organizational Resilience.” These issues of this series remain applicable today and, in many cases, are more important than ever, given the rapid changes of the last few years. But the term "resilience" can be difficult to define, and when we define it, we may limit its scope, missing the big picture.In the age of generative artificial intelligence (gen AI), the prevalence of breach data from infostealers and the near-constant…

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Protecting your digital assets from non-human identity attacks

4 min read - Untethered data accessibility and workflow automation are now foundational elements of most digital infrastructures. With the right applications and protocols in place, businesses no longer need to feel restricted by their lack of manpower or technical capabilities — machines are now filling those gaps.The use of non-human identities (NHIs) to power business-critical applications — especially those used in cloud computing environments or when facilitating service-to-service connections — has opened the doors for seamless operational efficiency. Unfortunately, these doors aren’t the…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today