cognitive cybersecurity intelligence

News and Analysis

Search

Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs

Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs

Windows users looking for a familiar cleanup utility are being steered toward a convincing counterfeit download page.

The file they receive installs GhostDesk, a malicious Chrome extension built to watch activity inside the browser.

The campaign turns a routine software download into a pathway for credential theft, keystroke capture, screenshots, cookie collection, and commands delivered to browser tabs.

Its use of a trusted application name shows why a polished page and familiar icon cannot establish that a download is safe.

Malwarebytes said in a report shared with Cyber Security News (CSN) that the operation begins with a fake CCleaner site and proceeds through a multi-stage Windows infection.

The researchers found the lure at ccleanerwind[.]top, where both displayed download choices served the same harmful executable.

The immediate impact is potentially serious for anyone who uses Chrome for email, banking, work portals, or cryptocurrency services.

Fake application (Source – Malwarebytes)

Unlike a noisy pop-up campaign, GhostDesk is designed to run in the background, leaving victims unaware that browser data may be exposed.

Fake CCleaner Download Delivers GhostDesk

The counterfeit installer uses the CCleaner name and icon, but its internal name and original filename do not match known releases.

It drops Windows Script Host’s CScript component, gathers basic device details, and replaces a Runtime Broker library with a loader for the next stage.

It then alters Chrome’s Security Extension manifest so two scripts, content.js and background.js, load from a local folder when the browser starts.

This technique echoes the risk described in malicious extension backdoor campaign, where a rogue add-on can establish enduring browser access.

The altered extension calls itself GhostDesk, a label also used by legitimate screen-overlay software.

That naming choice may make its screen capture role appear less unusual, but the reported functions point to surveillance rather than a normal browser tool.

Malicious Chrome extension (Source – Malwarebytes)

GhostDesk records entries typed into form fields and looks for submitted data tied to credentials, authentication tokens, and financial information.

It can also replace pasted cryptocurrency addresses, a tactic that could redirect a payment without changing what a victim intended to do.

Browser Spyware Raises Stakes

The background component can collect browser cookies, capture the active tab, maintain a local relay, and inject attacker-provided JavaScript into an open page.

Such broad permissions show why reviewing browser extension permissions should be part of routine account protection, especially on devices used for sensitive work.

The malware connects through a local WebSocket endpoint before reaching attacker infrastructure, allowing data and instructions to move between Chrome and the operator.

Comparable campaigns have used browser add-ons to quietly gather data at scale, including the long-running ShadyPanda extension campaign, which relied on trusted-looking extensions.

Researchers also traced the same loading method to fake 7-Zip and Adobe Acrobat samples, with all observed samples communicating with the same command-and-control domain.

One fake Adobe Acrobat variant used wscript.exe rather than cscript.exe, suggesting the operators can adjust the loader while keeping the broader delivery chain intact.

Anyone who downloaded the suspected installer should disconnect the machine from sensitive accounts, run a reputable security scan as soon as possible, and remove unfamiliar Chrome extensions.

They should also change passwords from a known-clean device, invalidate all account sessions where possible, and watch for unusual sign-ins or unauthorized transactions.

Because stolen cookies can bypass a password alone, prompt session revocation matters alongside credential resets.

Users should check the address bar carefully before downloading software and avoid treating sponsored results, social posts, text messages, or emailed links as proof that a download is official.

When available, obtain software through the publisher’s legitimate site or a trusted store, keep Windows and Chrome updated, and review recent extensions for anything unfamiliar.

The recent fake GoogleTranslate extension case is another reminder that a familiar name can hide tools built to steal browser data and remotely control sessions.

Indicators of Compromise (IoCs):-

TypeIndicatorDescriptionDomainccleanerwind[.]topFake CCleaner download websiteDomainliderongrade.duckdns[.]orgCommand-and-control serverIP Address193.169.240[.]81Command-and-control serverSHA-256c0b4a4af8a3a8c4b113d7f203fcf480cfac79160102490daf287748634b9ce23FakeCCleaner.exeSHA-2568d921bdd1f5bc8c03209a5dfacfd9ed313497ac2e3f1b4a2000f4c474a464904Reflexive loader replacing runtimebroker.dllSHA-2563d7411e2e445a2210dbbf061f3e8e3dd3476a4fc5d4a2135dcceb0bc705776bfcontent.js GhostDesk extensionSHA-256cfd9c0bcc89ebc68aae889b9b49bc8290c3764bce5f2c9ac8b5ba0ba58e9bf61background.js GhostDesk extensionSHA-256590b04e35fc0b3dcd9dabe82f2e96d4d1e0fccc598911cf80f8255232ee75fcbFake 7-Zip sampleSHA-256ecde892dbc28af620ba8e311fa9dd4c66521c7fe95e6aadacc7cd9a5bb57d32dFake Adobe Acrobat sampleSHA-256cfa3900cefb447d89a7498224f2ecafa65b190336934811e6c1d4196d9b92452Fake Adobe Acrobat sampleSHA-2560bf8f52b28291edc505a64962e6ce04387a9784fc5b18aeff53629adb1f72f56Fake Adobe Acrobat sample using wscript.exe

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
The post Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts