• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 25, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Malware
  • CCleaner is infected with malware – everything you need to know
  • Malware

CCleaner is infected with malware – everything you need to know

Ddos September 19, 2017 2 minutes read
cclean

CCleaner is a more than 2 billion download of Internet security software, the latest version of the hacker attack hijacked to distribute the user with the back door of the malicious software, the infected version was 227 million people to use. If you downloaded or updated the CCleaner application from your website on August 15th to September 12th, your computer has been compromised! Here’s what you need to know and how to deal with the program:

What happened?

An unknown hacker organization invaded the CCleaner infrastructure.

The attacker added malware to the 32-bit CCleaner version 5.33.6162 and the CCleaner Cloud version 1.07.3191.

This part of the file will affect users who have downloaded CCleaner software between August 15 and September 12 this year.

Who will be affected?

Every user who has downloaded and installed this infected version within the above period will be affected.

Avast estimates that the number of affected equipment is 2.27 million units.

What is the trouble with the malware?

This malware, called Floxif, collects all types of data from infected computers, including the computer name, the list of installed software, the list of currently running processes, the MAC addresses of the first three network interfaces, and the specifics of each computer Unique ID and so on.

The malware will also download and execute other malware, but Avast says it has not yet found evidence that an attacker has used this feature.

How to fix?

This malware is embedded into CCleaner’s executable file. Upgrade CCleaner to v5.34 to remove old executables and the malware. CCleaner does not automatically update, so users must manually download and install CCleaner 5.34.

Avast pointed out that it has already been updated for CCleaner Cloud users, so this part of the user will not be affected. The current clean version of CCleaner Cloud is 1.07.3214.

What are the details?

This malware will only be executed when the user is using an administrator account. If you use a low-privilege account to install CCleaner 5.33, it will not be affected. But still, recommend that you update to 5.34 version.

Why can anti-virus software not find this infection?

The malware included in the CCleaner library has a valid digital certificate signature.

Note:

you can read ccleaner malware analysis here.

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. Avast: corrupted CCleaner was downloaded 2.27 million times in September last year
  2. Beware of Fake Downloads: AsyncRAT Spreads via Popular Software Cracks
  3. Alert: “Brokewell” Malware – New Threat Targets Bank Users with Remote Device Takeover
  4. Malicious npm Packages Target Solana Developers, Stealing Private Keys via Gmail
  5. Chinese Hackers Exploit Exposed ASP.NET Keys to Deploy TOLLBOOTH IIS Backdoor and Kernel Rootkit
Tags: CCleaner Floxif

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚑

Get notified instantly when a Proof of Concept (PoC) exploit is published.

πŸ”

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

πŸ“Š

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

πŸ”΄ Live Critical Threats

  • CVE-2026-9458CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is...
  • CVE-2026-9457CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9456CVSS 9.8
    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function...
  • CVE-2026-9455CVSS 9.8
    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
  • CVE-2026-9454CVSS 9.8
    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects...
  • CVE-2026-9436CVSS 9.8
    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element...
  • CVE-2026-9435CVSS 9.8
    A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9434CVSS 9.8
    A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. Impacted is...
  • CVE-2026-9433CVSS 9.8
    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
  • CVE-2026-2651CVSS 9.0
    A vulnerability in MLflow versions
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity Β© All rights reserved.