Overview
A new malware campaign is tricking Windows users into downloading a fake CCleaner installer that secretly deploys GhostDesk, a malicious Chrome extension designed for surveillance. The counterfeit site, ccleanerwind[.]top, delivers spyware that can steal credentials, capture keystrokes, take screenshots, hijack cryptocurrency transactions, and inject attacker‑controlled scripts into browser tabs.
How the Attack Works
- Fake CCleaner site: Victims are lured to a polished download page mimicking the popular cleanup utility.
- Trojanized installer: The executable drops Windows Script Host’s CScript, collects device details, and replaces a Runtime Broker library with a malicious loader.
- Chrome extension hijack: Alters Chrome’s Security Extension manifest to load
content.jsandbackground.jsfrom local folders. - GhostDesk spyware: Records form entries, steals authentication tokens, replaces cryptocurrency addresses, and captures browser cookies.
Technical Details
- Persistence: GhostDesk runs silently in the background, maintaining a local relay via WebSocket before connecting to attacker infrastructure.
- Command‑and‑control (C2): Communicates with liderongrade.duckdns[.]org and IP 193.169.240[.]81.
- IoCs:
- Domains:
ccleanerwind[.]top,liderongrade.duckdns[.]org. - Files:
FakeCCleaner.exe,sopravpn_v7__1_.exe,runtimebroker.dllloader. - Hashes:
c0b4a4af8a3a8c4b113d7f203fcf480cfac79160102490daf287748634b9ce23(FakeCCleaner.exe).
- Domains:
Why It Matters
- Credential theft: GhostDesk targets email, banking, work portals, and cryptocurrency services.
- Silent surveillance: Unlike noisy pop‑ups, GhostDesk operates covertly, leaving victims unaware.
- Broader campaign links: Similar techniques were observed in fake 7‑Zip and Adobe Acrobat installers, all tied to the same attacker infrastructure.
Defensive Guidance
- Disconnect compromised devices: Immediately isolate affected systems.
- Run security scans: Use reputable antivirus tools to remove GhostDesk.
- Reset credentials: Change passwords from a clean device and revoke sessions.
- Check Chrome extensions: Remove suspicious add‑ons.
- Download only from official sources: Avoid sponsored links, social posts, or third‑party sites.
Expert in the Cloud Insight
This campaign highlights how attackers exploit trusted brand names to deliver spyware. A familiar icon and polished page are no guarantee of safety. For defenders, the lesson is clear: browser extensions are powerful attack surfaces, and vigilance around downloads is essential. GhostDesk shows how a single fake installer can escalate into full browser compromise, credential theft, and financial fraud.
Leave a Reply