One of the most dangerous and effective tactics in any infection campaign is when an attacker manages to intervene in a product's distribution chain and pass off their malware as part of a legitimate update. That is exactly what happened with CCleaner, the popular maintenance software now owned by Avast. The backdoor was detected in the builds of 32-bit CCleaner and in a specific version of CCleaner Cloud. The good news is that (apparently) it didn't cause any damage, but precautions are recommended.
This isn't the first time this has happened, and I'm afraid it won't be the last. Infiltrating the update mechanism in any program can lead to a mass infection affecting hundreds of millions of users around the world. One of the most striking examples was seen at the end of June, when a variant of the Petya ransomware used updates from an accounting software in Ukraine as its distribution vector. However, today we face an infection whose destructive potential could have been much greater. The victim was CCleaner, a classic maintenance program developed by Piriform, now under Avast's wing.
Experts from Morphisec and the Talos Group at Cisco identified an integrated backdoor in the 32-bit CCleaner 5.33.6162 and CCleaner Cloud 1.07.3191 installers using new detection technology.
The installation builds and executables had received legitimate digital certificates issued by Symantec, with validity extending until October 10, 2018. The package is composed of command and control functions and a domain generation algorithm. Distribution of the infected software took place between August 15 and September 12, the date when Piriform released CCleaner 5.34. The Talos Group concludes that an external agent managed to compromise part of CCleaner's development environment, or alternatively, that it was someone within the organization.
What should users do from here? The recommendation is to generate a SHA256 hash of the main executable and the last installer you downloaded, and compare the results with these three strings:
- 6f7840c77f99049d788155c1351e1560b62b8ad18ad0e9adda8218b9f432f0a9
- 1a4a5123d7b2c534cb3e3168f7032cf9ebf38b9a2a97226d0fdb7933cf6030ff
- 36b36ee9515e0a60629d2c722b006b33e543dce1c8c2611053e0651a0bfdb2e9
If the result matches, that executable contains the malware. The next step is to open the Registry Editor, visit the "HKEY_LOCAL_MACHINE\Software\Piriform" path and check for any entry labeled Agomo. If it appears there, the malware is already in the system.
The final phase is to update CCleaner to version 5.34 as soon as possible (even if you don't use the 32-bit build, because the installer contains both), and do a full scan of the computer with an up-to-date antivirus or antimalware. Malwarebytes reported that their program already detects the infection, quarantines the executables, and blocks communication with the remote server. Talos's suggestion is more extreme: revert the system to a state prior to August 15, or reinstall Windows. On the other hand, Piriform says it's enough to update CCleaner and that only 2.27 million users were affected. We'll keep our radars on and report any news.
Talos Group, Morphisec