Chrome Spyware on Windows PCs

Overview

A new malware campaign is tricking Windows users into downloading a fake CCleaner installer that secretly deploys GhostDesk, a malicious Chrome extension designed for surveillance. The counterfeit site, ccleanerwind[.]top, delivers spyware that can steal credentials, capture keystrokes, take screenshots, hijack cryptocurrency transactions, and inject attacker‑controlled scripts into browser tabs.

How the Attack Works

  • Fake CCleaner site: Victims are lured to a polished download page mimicking the popular cleanup utility.
  • Trojanized installer: The executable drops Windows Script Host’s CScript, collects device details, and replaces a Runtime Broker library with a malicious loader.
  • Chrome extension hijack: Alters Chrome’s Security Extension manifest to load content.js and background.js from local folders.
  • GhostDesk spyware: Records form entries, steals authentication tokens, replaces cryptocurrency addresses, and captures browser cookies.

Technical Details

  • Persistence: GhostDesk runs silently in the background, maintaining a local relay via WebSocket before connecting to attacker infrastructure.
  • Command‑and‑control (C2): Communicates with liderongrade.duckdns[.]org and IP 193.169.240[.]81.
  • IoCs:
    • Domains: ccleanerwind[.]top, liderongrade.duckdns[.]org.
    • Files: FakeCCleaner.exe, sopravpn_v7__1_.exe, runtimebroker.dll loader.
    • Hashes: c0b4a4af8a3a8c4b113d7f203fcf480cfac79160102490daf287748634b9ce23 (FakeCCleaner.exe).

Why It Matters

  • Credential theft: GhostDesk targets email, banking, work portals, and cryptocurrency services.
  • Silent surveillance: Unlike noisy pop‑ups, GhostDesk operates covertly, leaving victims unaware.
  • Broader campaign links: Similar techniques were observed in fake 7‑Zip and Adobe Acrobat installers, all tied to the same attacker infrastructure.

Defensive Guidance

  • Disconnect compromised devices: Immediately isolate affected systems.
  • Run security scans: Use reputable antivirus tools to remove GhostDesk.
  • Reset credentials: Change passwords from a clean device and revoke sessions.
  • Check Chrome extensions: Remove suspicious add‑ons.
  • Download only from official sources: Avoid sponsored links, social posts, or third‑party sites.

Expert in the Cloud Insight

This campaign highlights how attackers exploit trusted brand names to deliver spyware. A familiar icon and polished page are no guarantee of safety. For defenders, the lesson is clear: browser extensions are powerful attack surfaces, and vigilance around downloads is essential. GhostDesk shows how a single fake installer can escalate into full browser compromise, credential theft, and financial fraud.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.