Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Fake CCleaner installs GhostDesk Chrome spyware

0
Medium
Published: 08/11/2026 (08/11/2026, 21:01:31 UTC)
Source: AlienVault OTX General

Description

A fraudulent version of the widely-used PC cleaning utility CCleaner is being distributed through a convincing imitation website to deploy GhostDesk, a malicious Chrome extension functioning as spyware. The attack begins when users download the fake application from a lookalike site, which then launches a multi-stage infection using CScript to modify Chrome's Security Extension and install malicious components. Once active, GhostDesk performs extensive surveillance including credential theft, keylogging, screenshot capture, cookie harvesting, and cryptojacking. The extension establishes command-and-control communications via WebSocket connections and can execute arbitrary code within browser tabs. Similar fake versions of other popular software like 7-Zip and Adobe Acrobat have been identified using identical infection techniques.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 10:03:57 UTC

Technical Analysis

This threat involves a fraudulent CCleaner installer distributed through a convincing imitation website. Upon installation, it launches a multi-stage infection chain using CScript to modify Chrome's Security Extension and install GhostDesk, a malicious Chrome extension functioning as spyware. GhostDesk performs extensive surveillance activities including credential theft, keylogging, screenshot capture, cookie harvesting, and cryptojacking. It establishes command-and-control communication via WebSocket connections and has the capability to execute arbitrary code within browser tabs. The infection technique is also observed in fake versions of other popular software such as 7-Zip and Adobe Acrobat.

Potential Impact

The GhostDesk spyware compromises user privacy and security by stealing credentials, logging keystrokes, capturing screenshots, harvesting cookies, and performing cryptojacking. The ability to execute arbitrary code within browser tabs and maintain persistent command-and-control communications increases the risk of further compromise and data exfiltration. This can lead to unauthorized access to sensitive information and system resources.

Defensive Guidance

No official patch or fix is available as this is a malware campaign involving fake software distribution. Mitigation involves user education to avoid downloading software from unverified or imitation websites. Security teams should block known malicious domains and IPs associated with this threat, such as 'ccleanerwind.top' and 'liderongrade.duckdns.org', and monitor for indicators of compromise including the listed hashes. Removing the malicious Chrome extension and scanning infected systems with updated anti-malware tools is recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware"]
Adversary
null
Pulse Id
6a7b8dab529ad28b12d29796
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip193.169.240.81

Domain

ValueDescriptionCopy
domainccleanerwind.top
domainliderongrade.duckdns.org

Hash

ValueDescriptionCopy
hashc0b4a4af8a3a8c4b113d7f203fcf480cfac79160102490daf287748634b9ce23
hash8d921bdd1f5bc8c03209a5dfacfd9ed313497ac2e3f1b4a2000f4c474a464904
hash3d7411e2e445a2210dbbf061f3e8e3dd3476a4fc5d4a2135dcceb0bc705776bf
hashcfd9c0bcc89ebc68aae889b9b49bc8290c3764bce5f2c9ac8b5ba0ba58e9bf61
hash590b04e35fc0b3dcd9dabe82f2e96d4d1e0fccc598911cf80f8255232ee75fcb
hashecde892dbc28af620ba8e311fa9dd4c66521c7fe95e6aadacc7cd9a5bb57d32d
hashcfa3900cefb447d89a7498224f2ecafa65b190336934811e6c1d4196d9b92452
hash0bf8f52b28291edc505a64962e6ce04387a9784fc5b18aeff53629adb1f72f56
hash0d6b27a00e79e8138b3d93b2c56b24d7
hasha9c499afa0278279acd80597cbfc1e47
hash5f7f11caf5992f370ed9657ff898b96fa4fe17ba
hashe4571f7b27285ddc0e39d005a9f1109a9335820d

Threat ID: 6a7c158ebf8831d5391cfb06

Added to database: 08/12/2026, 06:41:18 UTC

Last enriched: 08/12/2026, 10:03:57 UTC

Last updated: 08/12/2026, 18:17:30 UTC

Views: 19

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses