Fake CCleaner Downloads Deliver GhostDesk Spyware to Windows PCs
Key Takeaways Cybercriminals are distributing GhostDesk spyware through deceptive websites mimicking legitimate software, specifically CCleaner. The malware, delivered as a malicious Chrome...
Key Takeaways
- Cybercriminals are distributing GhostDesk spyware through deceptive websites mimicking legitimate software, specifically CCleaner.
- The malware, delivered as a malicious Chrome extension, enables extensive browser surveillance, including credential theft, keystroke logging, and screenshot capture.
- This campaign highlights the danger of relying solely on familiar branding or polished interfaces for software downloads, as the fake sites are highly convincing.
- The threat actors behind GhostDesk also employ similar tactics with fake 7-Zip and Adobe Acrobat installers, indicating a broader, coordinated operation.
- Users of Windows PCs who may have downloaded software from unofficial sources are at high risk of compromise, particularly those using Chrome for sensitive activities.
Windows users seeking to download popular utilities are encountering sophisticated counterfeit websites that distribute the GhostDesk spyware. This malicious Chrome extension is engineered to monitor and exfiltrate a wide range of browser activity, turning a seemingly innocuous software download into a significant security incident.
Table Of Content
The campaign, detailed in a report by Malwarebytes, leverages the trusted name of CCleaner to trick users into installing malware. Attackers have crafted highly convincing download pages, demonstrating that visual authenticity alone is insufficient to guarantee software legitimacy. The immediate consequences for victims could be severe, including the theft of credentials, financial information, and sensitive personal data.
GhostDesk Spyware Distribution
The operation begins with users visiting a deceptive website, such as ccleanerwind[.]top, which masquerades as an official CCleaner download portal. Regardless of the download option selected on these fake sites, victims receive a harmful executable. This installer, while bearing the CCleaner name and icon, deviates significantly from legitimate releases in its internal naming and original filename, as noted in the Malwarebytes report.
Upon execution, the malicious installer deploys CScript, a Windows Script Host component, to gather basic system information. It then replaces a legitimate Runtime Broker library with a loader, initiating the subsequent stages of the infection chain. This stealthy approach allows the malware to establish a foothold without immediate detection.
GhostDesk Chrome Extension Capabilities
The core of the attack lies in the GhostDesk Chrome extension. This extension modifies Chrome’s Security Extension manifest to load two malicious scripts, content.js and background.js, from a local directory each time the browser launches. This technique mirrors other sophisticated browser backdoor campaigns, enabling persistent access and control over the user’s browser environment.
The choice of the name “GhostDesk” is likely a deliberate attempt to blend in with legitimate screen-overlay software, making its presence less suspicious to the user. However, its reported functionalities are purely for surveillance: it records keystrokes, captures screenshots, and specifically targets form fields for credentials, authentication tokens, and financial data. Furthermore, GhostDesk can surreptitiously alter pasted cryptocurrency addresses, diverting funds without the victim’s knowledge or explicit action. This silent operation makes GhostDesk particularly dangerous, as victims may remain unaware of the compromise for extended periods.
Browser Spyware Elevates Risk
The background component of GhostDesk is highly versatile, capable of collecting browser cookies, capturing active browser tabs, maintaining a local data relay, and injecting arbitrary JavaScript into open web pages. These extensive permissions underscore the critical importance of regularly reviewing browser extension permissions, especially on devices used for sensitive tasks like online banking, email, or work-related portals.
GhostDesk communicates with attacker infrastructure through a local WebSocket endpoint, facilitating the covert exchange of data and commands between the compromised Chrome browser and the threat actors. This method of operation is consistent with other large-scale browser add-on campaigns, such as the persistent ShadyPanda operation, which also relied on extensions that appeared trustworthy to harvest data.
Researchers have identified that the same loading mechanism used by the fake CCleaner installer is also employed in counterfeit 7-Zip and Adobe Acrobat samples. All observed variants connect to the same command-and-control domain. Interestingly, one fake Adobe Acrobat sample utilized wscript.exe instead of cscript.exe, indicating the attackers’ flexibility in adapting their loader while maintaining the overarching delivery infrastructure.
What You Should Do
- Immediately Disconnect: If you suspect you downloaded software from an unofficial source, disconnect the affected machine from sensitive accounts (banking, email, work portals) and the network.
- Run a Comprehensive Security Scan: Perform a full system scan with reputable antivirus and anti-malware software.
- Remove Suspicious Extensions: Review all Chrome extensions and remove any unfamiliar or recently installed add-ons.
- Change Passwords and Invalidate Sessions: Change all passwords for critical accounts from a known-clean device. Where possible, revoke all active sessions for these accounts to force new logins.
- Monitor for Unusual Activity: Remain vigilant for any unusual login attempts or unauthorized transactions on your accounts.
- Verify Download Sources: Always download software directly from the official publisher’s website or trusted application stores. Avoid links from sponsored search results, social media posts, text messages, or emails.
- Keep Software Updated: Ensure your operating system (Windows) and web browser (Chrome) are always updated to the latest versions to benefit from security patches.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.