Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Windows users looking for a familiar cleanup utility are being steered toward a convincing counterfeit download page.

The file they receive installs GhostDesk, a malicious Chrome extension built to watch activity inside the browser.

The campaign turns a routine software download into a pathway for credential theft, keystroke capture, screenshots, cookie collection, and commands delivered to browser tabs.

Its use of a trusted application name shows why a polished page and familiar icon cannot establish that a download is safe.

Malwarebytes said in a report shared with Cyber Security News (CSN) that the operation begins with a fake CCleaner site and proceeds through a multi-stage Windows infection.

The researchers found the lure at ccleanerwind[.]top, where both displayed download choices served the same harmful executable.

The immediate impact is potentially serious for anyone who uses Chrome for email, banking, work portals, or cryptocurrency services.

Fake application (Source – Malwarebytes)

Unlike a noisy pop-up campaign, GhostDesk is designed to run in the background, leaving victims unaware that browser data may be exposed.

The counterfeit installer uses the CCleaner name and icon, but its internal name and original filename do not match known releases.

It drops Windows Script Host’s CScript component, gathers basic device details, and replaces a Runtime Broker library with a loader for the next stage.

It then alters Chrome’s Security Extension manifest so two scripts, content.js and background.js, load from a local folder when the browser starts.

This technique echoes the risk described in malicious extension backdoor campaign, where a rogue add-on can establish enduring browser access.

The altered extension calls itself GhostDesk, a label also used by legitimate screen-overlay software.

That naming choice may make its screen capture role appear less unusual, but the reported functions point to surveillance rather than a normal browser tool.

Malicious Chrome extension (Source – Malwarebytes)

GhostDesk records entries typed into form fields and looks for submitted data tied to credentials, authentication tokens, and financial information.

It can also replace pasted cryptocurrency addresses, a tactic that could redirect a payment without changing what a victim intended to do.

Browser Spyware Raises Stakes

The background component can collect browser cookies, capture the active tab, maintain a local relay, and inject attacker-provided JavaScript into an open page.

Such broad permissions show why reviewing browser extension permissions should be part of routine account protection, especially on devices used for sensitive work.

The malware connects through a local WebSocket endpoint before reaching attacker infrastructure, allowing data and instructions to move between Chrome and the operator.

Comparable campaigns have used browser add-ons to quietly gather data at scale, including the long-running ShadyPanda extension campaign, which relied on trusted-looking extensions.

Researchers also traced the same loading method to fake 7-Zip and Adobe Acrobat samples, with all observed samples communicating with the same command-and-control domain.

One fake Adobe Acrobat variant used wscript.exe rather than cscript.exe, suggesting the operators can adjust the loader while keeping the broader delivery chain intact.

Anyone who downloaded the suspected installer should disconnect the machine from sensitive accounts, run a reputable security scan as soon as possible, and remove unfamiliar Chrome extensions.

They should also change passwords from a known-clean device, invalidate all account sessions where possible, and watch for unusual sign-ins or unauthorized transactions.

Because stolen cookies can bypass a password alone, prompt session revocation matters alongside credential resets.

Users should check the address bar carefully before downloading software and avoid treating sponsored results, social posts, text messages, or emailed links as proof that a download is official.

When available, obtain software through the publisher’s legitimate site or a trusted store, keep Windows and Chrome updated, and review recent extensions for anything unfamiliar.

The recent fake GoogleTranslate extension case is another reminder that a familiar name can hide tools built to steal browser data and remotely control sessions.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain ccleanerwind[.]top Fake CCleaner download website
Domain liderongrade.duckdns[.]org Command-and-control server
IP Address 193.169.240[.]81 Command-and-control server
SHA-256 c0b4a4af8a3a8c4b113d7f203fcf480cfac79160102490daf287748634b9ce23 FakeCCleaner.exe
SHA-256 8d921bdd1f5bc8c03209a5dfacfd9ed313497ac2e3f1b4a2000f4c474a464904 Reflexive loader replacing runtimebroker.dll
SHA-256 3d7411e2e445a2210dbbf061f3e8e3dd3476a4fc5d4a2135dcceb0bc705776bf content.js GhostDesk extension
SHA-256 cfd9c0bcc89ebc68aae889b9b49bc8290c3764bce5f2c9ac8b5ba0ba58e9bf61 background.js GhostDesk extension
SHA-256 590b04e35fc0b3dcd9dabe82f2e96d4d1e0fccc598911cf80f8255232ee75fcb Fake 7-Zip sample
SHA-256 ecde892dbc28af620ba8e311fa9dd4c66521c7fe95e6aadacc7cd9a5bb57d32d Fake Adobe Acrobat sample
SHA-256 cfa3900cefb447d89a7498224f2ecafa65b190336934811e6c1d4196d9b92452 Fake Adobe Acrobat sample
SHA-256 0bf8f52b28291edc505a64962e6ce04387a9784fc5b18aeff53629adb1f72f56 Fake Adobe Acrobat sample using wscript.exe

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world