Csoonline Fake CCleaner Installer Distributes GhostDesk Spyware via Chrome
Article Content
- •A counterfeit CCleaner installer is distributing GhostDesk, a Chrome spyware extension.
- •The attack modifies Chrome's security settings to enable credential theft and surveillance.
- •The campaign also includes fake versions of 7-zip and Adobe Acrobat, expanding its reach.
A malicious version of the popular CCleaner utility is being used to install GhostDesk, a Chrome extension that steals credentials and monitors user activity. The attack begins when users download the counterfeit CCleaner from a fake site, ccleanerwind[.]top. This installer executes scripts that modify Chrome's security settings, allowing the malware to capture keystrokes, cookies, and screenshots. The campaign has been linked to additional fake applications, including 7-zip and Adobe Acrobat, indicating a broader distribution strategy. Malwarebytes researchers have identified the malicious scripts and their capabilities, raising concerns for enterprise security. With over 2 billion downloads of CCleaner globally, the attack targets a wide range of users seeking system maintenance tools. The ongoing threat is significant, given the sensitive data that can be compromised.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track GhostDesk and CVE-2026-59310 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Ransomware Exploits Critical VMware vCenter Vulnerability CVE-2026-59310 On September 15, 2026, CISA confirmed that ransomware gangs are actively exploiting a critical remote code execution vulnerability in VMware vCenter Server, tracked as CVE-2026-59310, which has a CVSS score of 9.8. This flaw, residing in the vCenter Syslog server, allows unauthenticated attackers with network access…
Critical Path Traversal Vulnerability in VMware vCenter Server A critical vulnerability, CVE-2026-59310, has been identified in VMware vCenter Server that allows for unauthorized remote code execution through a path traversal exploit. This flaw affects versions prior to 9.0.2.0 / Build 25148086, where attackers can exploit the syslog service by sending specially crafted messages…