home.social

#ccleaner — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #ccleaner, aggregated by home.social.

fetched live
  1. 🚨 Fake #CCleaner installs GhostDesk spyware

    The trojanized installer deploys Chrome-focused spyware to steal browser data.
    🔗 read more: www.malwarebytes.com...

    #ransomNews #cybersecurity

    Fake CCleaner installs GhostDe...

  2. Fake CCleaner installs GhostDesk Chrome spyware

    Pulse ID: 6a7d498dc95702116f348241
    Pulse Link: otx.alienvault.com/pulse/6a7d4
    Pulse Author: Tr1sa111
    Created: 2026-08-13 04:35:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CCleaner #Chrome #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #bot #Tr1sa111

  3. Fake CCleaner installs GhostDesk Chrome spyware

    Pulse ID: 6a7d498dc95702116f348241
    Pulse Link: otx.alienvault.com/pulse/6a7d4
    Pulse Author: Tr1sa111
    Created: 2026-08-13 04:35:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CCleaner #Chrome #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #bot #Tr1sa111

  4. Fake CCleaner installs GhostDesk Chrome spyware

    Pulse ID: 6a7d498dc95702116f348241
    Pulse Link: otx.alienvault.com/pulse/6a7d4
    Pulse Author: Tr1sa111
    Created: 2026-08-13 04:35:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CCleaner #Chrome #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #bot #Tr1sa111

  5. Fake CCleaner installs GhostDesk Chrome spyware

    Pulse ID: 6a7d498dc95702116f348241
    Pulse Link: otx.alienvault.com/pulse/6a7d4
    Pulse Author: Tr1sa111
    Created: 2026-08-13 04:35:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CCleaner #Chrome #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #bot #Tr1sa111

  6. Fake CCleaner installs GhostDesk Chrome spyware

    Pulse ID: 6a7d498dc95702116f348241
    Pulse Link: otx.alienvault.com/pulse/6a7d4
    Pulse Author: Tr1sa111
    Created: 2026-08-13 04:35:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CCleaner #Chrome #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #bot #Tr1sa111

  7. Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs

    Indicators extracted from public reporting. Source: malwarebytes.com/blog/threat-i

    Pulse ID: 6a7c6d5cf70eca6997f0ff3b
    Pulse Link: otx.alienvault.com/pulse/6a7c6
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 12:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #Windows #bot #CyberHunter_NL

  8. Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs

    Indicators extracted from public reporting. Source: malwarebytes.com/blog/threat-i

    Pulse ID: 6a7c6d5cf70eca6997f0ff3b
    Pulse Link: otx.alienvault.com/pulse/6a7c6
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 12:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #Windows #bot #CyberHunter_NL

  9. Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs

    Indicators extracted from public reporting. Source: malwarebytes.com/blog/threat-i

    Pulse ID: 6a7c6d5cf70eca6997f0ff3b
    Pulse Link: otx.alienvault.com/pulse/6a7c6
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 12:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #Windows #bot #CyberHunter_NL

  10. Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs

    Indicators extracted from public reporting. Source: malwarebytes.com/blog/threat-i

    Pulse ID: 6a7c6d5cf70eca6997f0ff3b
    Pulse Link: otx.alienvault.com/pulse/6a7c6
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 12:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #Windows #bot #CyberHunter_NL

  11. Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs

    Indicators extracted from public reporting. Source: malwarebytes.com/blog/threat-i

    Pulse ID: 6a7c6d5cf70eca6997f0ff3b
    Pulse Link: otx.alienvault.com/pulse/6a7c6
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 12:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #Windows #bot #CyberHunter_NL

  12. Fake CCleaner installs GhostDesk Chrome spyware

    A fraudulent version of the widely-used PC cleaning utility CCleaner is being distributed through a convincing imitation website to deploy GhostDesk, a malicious Chrome extension functioning as spyware. The attack begins when users download the fake application from a lookalike site, which then launches a multi-stage infection using CScript to modify Chrome's Security Extension and install malicious components. Once active, GhostDesk performs extensive surveillance including credential theft, keylogging, screenshot capture, cookie harvesting, and cryptojacking. The extension establishes command-and-control communications via WebSocket connections and can execute arbitrary code within browser tabs. Similar fake versions of other popular software like 7-Zip and Adobe Acrobat have been identified using identical infection techniques.

    Pulse ID: 6a7b8dab529ad28b12d29796
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: AlienVault
    Created: 2026-08-11 21:01:31

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #Browser #CCleaner #Chrome #ChromeExtension #CryptoJacking #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #ZIP #bot #AlienVault

  13. Fake CCleaner installs GhostDesk Chrome spyware

    A fraudulent version of the widely-used PC cleaning utility CCleaner is being distributed through a convincing imitation website to deploy GhostDesk, a malicious Chrome extension functioning as spyware. The attack begins when users download the fake application from a lookalike site, which then launches a multi-stage infection using CScript to modify Chrome's Security Extension and install malicious components. Once active, GhostDesk performs extensive surveillance including credential theft, keylogging, screenshot capture, cookie harvesting, and cryptojacking. The extension establishes command-and-control communications via WebSocket connections and can execute arbitrary code within browser tabs. Similar fake versions of other popular software like 7-Zip and Adobe Acrobat have been identified using identical infection techniques.

    Pulse ID: 6a7b8dab529ad28b12d29796
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: AlienVault
    Created: 2026-08-11 21:01:31

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #Browser #CCleaner #Chrome #ChromeExtension #CryptoJacking #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #ZIP #bot #AlienVault

  14. Fake CCleaner installs GhostDesk Chrome spyware

    A fraudulent version of the widely-used PC cleaning utility CCleaner is being distributed through a convincing imitation website to deploy GhostDesk, a malicious Chrome extension functioning as spyware. The attack begins when users download the fake application from a lookalike site, which then launches a multi-stage infection using CScript to modify Chrome's Security Extension and install malicious components. Once active, GhostDesk performs extensive surveillance including credential theft, keylogging, screenshot capture, cookie harvesting, and cryptojacking. The extension establishes command-and-control communications via WebSocket connections and can execute arbitrary code within browser tabs. Similar fake versions of other popular software like 7-Zip and Adobe Acrobat have been identified using identical infection techniques.

    Pulse ID: 6a7b8dab529ad28b12d29796
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: AlienVault
    Created: 2026-08-11 21:01:31

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #Browser #CCleaner #Chrome #ChromeExtension #CryptoJacking #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #ZIP #bot #AlienVault

  15. Fake CCleaner installs GhostDesk Chrome spyware

    A fraudulent version of the widely-used PC cleaning utility CCleaner is being distributed through a convincing imitation website to deploy GhostDesk, a malicious Chrome extension functioning as spyware. The attack begins when users download the fake application from a lookalike site, which then launches a multi-stage infection using CScript to modify Chrome's Security Extension and install malicious components. Once active, GhostDesk performs extensive surveillance including credential theft, keylogging, screenshot capture, cookie harvesting, and cryptojacking. The extension establishes command-and-control communications via WebSocket connections and can execute arbitrary code within browser tabs. Similar fake versions of other popular software like 7-Zip and Adobe Acrobat have been identified using identical infection techniques.

    Pulse ID: 6a7b8dab529ad28b12d29796
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: AlienVault
    Created: 2026-08-11 21:01:31

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #Browser #CCleaner #Chrome #ChromeExtension #CryptoJacking #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #ZIP #bot #AlienVault

  16. Fake CCleaner installs GhostDesk Chrome spyware

    A fraudulent version of the widely-used PC cleaning utility CCleaner is being distributed through a convincing imitation website to deploy GhostDesk, a malicious Chrome extension functioning as spyware. The attack begins when users download the fake application from a lookalike site, which then launches a multi-stage infection using CScript to modify Chrome's Security Extension and install malicious components. Once active, GhostDesk performs extensive surveillance including credential theft, keylogging, screenshot capture, cookie harvesting, and cryptojacking. The extension establishes command-and-control communications via WebSocket connections and can execute arbitrary code within browser tabs. Similar fake versions of other popular software like 7-Zip and Adobe Acrobat have been identified using identical infection techniques.

    Pulse ID: 6a7b8dab529ad28b12d29796
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: AlienVault
    Created: 2026-08-11 21:01:31

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #Browser #CCleaner #Chrome #ChromeExtension #CryptoJacking #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #ZIP #bot #AlienVault

  17. Fake CCleaner installs GhostDesk Chrome spyware

    Indicators extracted from public reporting. Source: malwarebytes.com/blog/threat-i

    Pulse ID: 6a7b8c83bf51f40e5a39c8e5
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 20:56:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #bot #CyberHunter_NL

  18. Fake CCleaner installs GhostDesk Chrome spyware

    Indicators extracted from public reporting. Source: malwarebytes.com/blog/threat-i

    Pulse ID: 6a7b8c83bf51f40e5a39c8e5
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 20:56:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #bot #CyberHunter_NL

  19. Fake CCleaner installs GhostDesk Chrome spyware

    Indicators extracted from public reporting. Source: malwarebytes.com/blog/threat-i

    Pulse ID: 6a7b8c83bf51f40e5a39c8e5
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 20:56:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #bot #CyberHunter_NL

  20. Fake CCleaner installs GhostDesk Chrome spyware

    Indicators extracted from public reporting. Source: malwarebytes.com/blog/threat-i

    Pulse ID: 6a7b8c83bf51f40e5a39c8e5
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 20:56:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #bot #CyberHunter_NL

  21. Fake CCleaner installs GhostDesk Chrome spyware

    Indicators extracted from public reporting. Source: malwarebytes.com/blog/threat-i

    Pulse ID: 6a7b8c83bf51f40e5a39c8e5
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 20:56:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #bot #CyberHunter_NL

  22. Learn why CCleaner is useless on Linux and macOS and the 5 commands you actually need to keep your Linux system clean, plus what macOS users should do instead.

    Full guide here: ostechnix.com/ccleaner-is-usel

    #ccleaner #linux #macos

  23. Learn why CCleaner is useless on Linux and macOS and the 5 commands you actually need to keep your Linux system clean, plus what macOS users should do instead.

    Full guide here: ostechnix.com/ccleaner-is-usel

    #ccleaner #linux #macos

  24. Learn why CCleaner is useless on Linux and macOS and the 5 commands you actually need to keep your Linux system clean, plus what macOS users should do instead.

    Full guide here: ostechnix.com/ccleaner-is-usel

    #ccleaner #linux #macos

  25. Learn why CCleaner is useless on Linux and macOS and the 5 commands you actually need to keep your Linux system clean, plus what macOS users should do instead.

    Full guide here: ostechnix.com/ccleaner-is-usel

    #ccleaner #linux #macos

  26. Learn why CCleaner is useless on Linux and macOS and the 5 commands you actually need to keep your Linux system clean, plus what macOS users should do instead.

    Full guide here: ostechnix.com/ccleaner-is-usel

    #ccleaner #linux #macos

  27. "I stopped using #CCleaner and #Windows tools did the same job"

    What finally changed wasn’t CCleaner itself, but Windows. As the operating system matured, it started taking over the same #cleanup tasks that once required a third-party tool.

    #StorageSense handles everyday cleanup

    Settings -> System -> Storage

    makeuseof.com/i-stopped-using-

  28. "I stopped using #CCleaner and #Windows tools did the same job"

    What finally changed wasn’t CCleaner itself, but Windows. As the operating system matured, it started taking over the same #cleanup tasks that once required a third-party tool.

    #StorageSense handles everyday cleanup

    Settings -> System -> Storage

    makeuseof.com/i-stopped-using-

  29. "I stopped using #CCleaner and #Windows tools did the same job"

    What finally changed wasn’t CCleaner itself, but Windows. As the operating system matured, it started taking over the same #cleanup tasks that once required a third-party tool.

    #StorageSense handles everyday cleanup

    Settings -> System -> Storage

    makeuseof.com/i-stopped-using-

  30. "I stopped using #CCleaner and #Windows tools did the same job"

    What finally changed wasn’t CCleaner itself, but Windows. As the operating system matured, it started taking over the same #cleanup tasks that once required a third-party tool.

    #StorageSense handles everyday cleanup

    Settings -> System -> Storage

    makeuseof.com/i-stopped-using-

  31. "I stopped using #CCleaner and #Windows tools did the same job"

    What finally changed wasn’t CCleaner itself, but Windows. As the operating system matured, it started taking over the same #cleanup tasks that once required a third-party tool.

    #StorageSense handles everyday cleanup

    Settings -> System -> Storage

    makeuseof.com/i-stopped-using-

  32. ⚠️ VORSICHT: #CCleaner #PayPal #Phishing ! ⚠️

    (Aber bitte keine Diskussion über den CCleaner. 😏)

  33. La #merdification du jour : #CCleaner, dont la dernière version fait passer certaines fonctions en mode payant. Et impossible de rester sur une ancienne version : il semble que la mise à jour vers la dernière est forcée par le logiciel.

    Bah, vous me direz : ces “utilitaires” ont toujours fait plus de mal que de bien à Windows, donc raison de plus pour les dégager et ne jamais les installer ! 🚮

  34. La #merdification du jour : #CCleaner, dont la dernière version fait passer certaines fonctions en mode payant. Et impossible de rester sur une ancienne version : il semble que la mise à jour vers la dernière est forcée par le logiciel.

    Bah, vous me direz : ces “utilitaires” ont toujours fait plus de mal que de bien à Windows, donc raison de plus pour les dégager et ne jamais les installer ! 🚮

  35. La #merdification du jour : #CCleaner, dont la dernière version fait passer certaines fonctions en mode payant. Et impossible de rester sur une ancienne version : il semble que la mise à jour vers la dernière est forcée par le logiciel.

    Bah, vous me direz : ces “utilitaires” ont toujours fait plus de mal que de bien à Windows, donc raison de plus pour les dégager et ne jamais les installer ! 🚮

  36. La #merdification du jour : #CCleaner, dont la dernière version fait passer certaines fonctions en mode payant. Et impossible de rester sur une ancienne version : il semble que la mise à jour vers la dernière est forcée par le logiciel.

    Bah, vous me direz : ces “utilitaires” ont toujours fait plus de mal que de bien à Windows, donc raison de plus pour les dégager et ne jamais les installer ! 🚮

  37. #CCleaner
    もしかして…と、#Firefox の履歴を確認したら、削除されてない!
    「CCleaner 7」でクリーニングしたのに、「CCleaner 7」の設定では履歴を削除するようにしてあるのに…。

    デフォルトのフォルダーしか見てないのだろうな。以前のバージョンではちゃんと削除してくれた。
    クッキーが削除されなかったのも、「CCleaner 7」がデフォルトのフォルダーしか見てなかったからだろう。
    必要なクッキーが削除されなくて良かった…。

    役立たずになったことが分かったので、「CCleaner 7」はアンインストールする。決定!

  38. #CCleaner war ein nettes, kostenloses Programm zur Bereinigung der Cache-Speicher und der Registry. Dann wurde es von Avast gekauft. Zuerst wurden nervigen Popups für kostenpflichtigen Dreck eingeführt und nun haben sie die ursprüngliche Grundfunktion des Programms verhunzt. Schade! 🙄

  39. #CCleaner war ein nettes, kostenloses Programm zur Bereinigung der Cache-Speicher und der Registry. Dann wurde es von Avast gekauft. Zuerst wurden nervigen Popups für kostenpflichtigen Dreck eingeführt und nun haben sie die ursprüngliche Grundfunktion des Programms verhunzt. Schade! 🙄

  40. #CCleaner war ein nettes, kostenloses Programm zur Bereinigung der Cache-Speicher und der Registry. Dann wurde es von Avast gekauft. Zuerst wurden nervigen Popups für kostenpflichtigen Dreck eingeführt und nun haben sie die ursprüngliche Grundfunktion des Programms verhunzt. Schade! 🙄

  41. #メモ #CCleaner #バグ
    CCleaner はコンピュータをより速く、より安全に | 公式ウェブサイト
    ccleaner.com/ja-jp

    書き込みエラーでアップデートできなかった。

  42. Lleva un tiempecito, pero ahí va.
    Nueva #actualizacion de #Bleachbit con mejoras de seguridad y reconocimiento y limpieza de más programas.
    Configuradlo con cuidado si no queréis perder algún ajuste o sesión de navegador, ya que esto limpia a conciencia y debe usarse igual de concienzudamente.
    Si no conoces este programa y sigues usando #CCleaner aun estás a tiempo de salir de la edad de piedra. Pruébalo y verás la diferencia.

    alternativeto.net/news/2025/5/

    #actualizaciones

  43. Lleva un tiempecito, pero ahí va.
    Nueva #actualizacion de #Bleachbit con mejoras de seguridad y reconocimiento y limpieza de más programas.
    Configuradlo con cuidado si no queréis perder algún ajuste o sesión de navegador, ya que esto limpia a conciencia y debe usarse igual de concienzudamente.
    Si no conoces este programa y sigues usando #CCleaner aun estás a tiempo de salir de la edad de piedra. Pruébalo y verás la diferencia.

    alternativeto.net/news/2025/5/

    #actualizaciones

  44. Lleva un tiempecito, pero ahí va.
    Nueva #actualizacion de #Bleachbit con mejoras de seguridad y reconocimiento y limpieza de más programas.
    Configuradlo con cuidado si no queréis perder algún ajuste o sesión de navegador, ya que esto limpia a conciencia y debe usarse igual de concienzudamente.
    Si no conoces este programa y sigues usando #CCleaner aun estás a tiempo de salir de la edad de piedra. Pruébalo y verás la diferencia.

    alternativeto.net/news/2025/5/

    #actualizaciones

  45. Lleva un tiempecito, pero ahí va.
    Nueva #actualizacion de #Bleachbit con mejoras de seguridad y reconocimiento y limpieza de más programas.
    Configuradlo con cuidado si no queréis perder algún ajuste o sesión de navegador, ya que esto limpia a conciencia y debe usarse igual de concienzudamente.
    Si no conoces este programa y sigues usando #CCleaner aun estás a tiempo de salir de la edad de piedra. Pruébalo y verás la diferencia.

    alternativeto.net/news/2025/5/

    #actualizaciones

  46. Just had a message saying I needed to update #Ccleaner. Looked suspicious, because doesn’t Ccleaner update itself? Opened the program, and it says I am using the latest edition. Suspicion: this wasn’t from the web, but Ccleaner purposely confusing the words update and upgrade, tricking users into paying.

  47. Just had a message saying I needed to update #Ccleaner. Looked suspicious, because doesn’t Ccleaner update itself? Opened the program, and it says I am using the latest edition. Suspicion: this wasn’t from the web, but Ccleaner purposely confusing the words update and upgrade, tricking users into paying.

  48. Just had a message saying I needed to update #Ccleaner. Looked suspicious, because doesn’t Ccleaner update itself? Opened the program, and it says I am using the latest edition. Suspicion: this wasn’t from the web, but Ccleaner purposely confusing the words update and upgrade, tricking users into paying.

  49. Just had a message saying I needed to update #Ccleaner. Looked suspicious, because doesn’t Ccleaner update itself? Opened the program, and it says I am using the latest edition. Suspicion: this wasn’t from the web, but Ccleaner purposely confusing the words update and upgrade, tricking users into paying.

  50. Just had a message saying I needed to update #Ccleaner. Looked suspicious, because doesn’t Ccleaner update itself? Opened the program, and it says I am using the latest edition. Suspicion: this wasn’t from the web, but Ccleaner purposely confusing the words update and upgrade, tricking users into paying.

  51. Подельники или подражатели? Подробности атак группировки PhaseShifters

    С весны 2023 года мы активно наблюдаем за одной любопытной группировкой. Мы назвали ее PhaseShifters, так как заметили, что она меняет свои техники вслед за другим группировками, например UAC-0050 и TA558. В своих атаках PhaseShifters используют фишинг от имени официальных лиц с просьбой ознакомиться с документами и их подписать. А эти документы, в свою очередь, защищены паролем и (что предсказуемо) заражены. В качестве ВПО злоумышленники используют Rhadamanthys, DarkTrack RAT, Meta Stealer — часть этих инструментов мы заметили у UAC-0050. А использованные криптеры были те же, что и у группировок TA558 и Blind Eagle. Кто у кого списал?

    habr.com/ru/companies/pt/artic

    #apt #cybersecurity #вредоносное_по #ccleaner #стеганография #расследование #кибергруппировки #bitbucket #darktrack_rat

  52. Подельники или подражатели? Подробности атак группировки PhaseShifters

    С весны 2023 года мы активно наблюдаем за одной любопытной группировкой. Мы назвали ее PhaseShifters, так как заметили, что она меняет свои техники вслед за другим группировками, например UAC-0050 и TA558. В своих атаках PhaseShifters используют фишинг от имени официальных лиц с просьбой ознакомиться с документами и их подписать. А эти документы, в свою очередь, защищены паролем и (что предсказуемо) заражены. В качестве ВПО злоумышленники используют Rhadamanthys, DarkTrack RAT, Meta Stealer — часть этих инструментов мы заметили у UAC-0050. А использованные криптеры были те же, что и у группировок TA558 и Blind Eagle. Кто у кого списал?

    habr.com/ru/companies/pt/artic

    #apt #cybersecurity #вредоносное_по #ccleaner #стеганография #расследование #кибергруппировки #bitbucket #darktrack_rat

  53. Подельники или подражатели? Подробности атак группировки PhaseShifters

    С весны 2023 года мы активно наблюдаем за одной любопытной группировкой. Мы назвали ее PhaseShifters, так как заметили, что она меняет свои техники вслед за другим группировками, например UAC-0050 и TA558. В своих атаках PhaseShifters используют фишинг от имени официальных лиц с просьбой ознакомиться с документами и их подписать. А эти документы, в свою очередь, защищены паролем и (что предсказуемо) заражены. В качестве ВПО злоумышленники используют Rhadamanthys, DarkTrack RAT, Meta Stealer — часть этих инструментов мы заметили у UAC-0050. А использованные криптеры были те же, что и у группировок TA558 и Blind Eagle. Кто у кого списал?

    habr.com/ru/companies/pt/artic

    #apt #cybersecurity #вредоносное_по #ccleaner #стеганография #расследование #кибергруппировки #bitbucket #darktrack_rat

  54. CCleanerのバグらしき動作。もしかしたら、#Firefox でもよく起こる。アイコンなどの表示の失敗が起こっていたのかもしれない。気づかなかったけれど…。昔はアイコンに画像ファイル的なものが使われていたのだけど、最近は何らかのコードを変換して画像にするようなことが多く、#Outlookでは、その読み込みというか表示に失敗して延々と読み込み中になることがある。それと同じようなことが #CCleaner でも起こっていたのかもしれない。

  55. It has been a while since I’ve written about Avast, so today I give you “How insecure is Avast Secure Browser?”

    palant.info/2024/07/15/how-ins

    Note: This isn’t a vulnerability disclosure, merely an overview of problematic design decisions.

    TL;DR from the article: I wouldn’t run Avast Secure Browser on any real operating system, only inside a virtual machine containing no data whatsoever.

    Some highlights:

    • Eleven pre-installed browser extensions but only two visible to users.
    • Two extensions unnecessarily relax Content-Security-Policy protection.
    • One of these two extensions also requesting all privileges possible, despite not actually using them.
    • Two extensions accept messages from any other extension and any Avast website, the latter without enforcing HTTPS connections.
    • One of these extensions, Privacy Guard (sic!), will expose information about your browser’s tabs via that messaging interface and provide updates as you browse the web.
    • The “onboarding” experience is designed as an extremely flexible way to nag you into using products that benefit Avast financially.
    • To make this “onboarding” work, the browser exposes internal APIs to a number of Avast domains that a huge number of third parties can put content on. Not only can each of these third parties abuse this access, a single XSS vulnerability will extend the access to any website on the internet (no effective CSP protection).

    Enjoy!

    #avast #avg #avira #ccleaner #securebrowser #infosec

  56. It has been a while since I’ve written about Avast, so today I give you “How insecure is Avast Secure Browser?”

    palant.info/2024/07/15/how-ins

    Note: This isn’t a vulnerability disclosure, merely an overview of problematic design decisions.

    TL;DR from the article: I wouldn’t run Avast Secure Browser on any real operating system, only inside a virtual machine containing no data whatsoever.

    Some highlights:

    • Eleven pre-installed browser extensions but only two visible to users.
    • Two extensions unnecessarily relax Content-Security-Policy protection.
    • One of these two extensions also requesting all privileges possible, despite not actually using them.
    • Two extensions accept messages from any other extension and any Avast website, the latter without enforcing HTTPS connections.
    • One of these extensions, Privacy Guard (sic!), will expose information about your browser’s tabs via that messaging interface and provide updates as you browse the web.
    • The “onboarding” experience is designed as an extremely flexible way to nag you into using products that benefit Avast financially.
    • To make this “onboarding” work, the browser exposes internal APIs to a number of Avast domains that a huge number of third parties can put content on. Not only can each of these third parties abuse this access, a single XSS vulnerability will extend the access to any website on the internet (no effective CSP protection).

    Enjoy!

    #avast #avg #avira #ccleaner #securebrowser #infosec

  57. It has been a while since I’ve written about Avast, so today I give you “How insecure is Avast Secure Browser?”

    palant.info/2024/07/15/how-ins

    Note: This isn’t a vulnerability disclosure, merely an overview of problematic design decisions.

    TL;DR from the article: I wouldn’t run Avast Secure Browser on any real operating system, only inside a virtual machine containing no data whatsoever.

    Some highlights:

    • Eleven pre-installed browser extensions but only two visible to users.
    • Two extensions unnecessarily relax Content-Security-Policy protection.
    • One of these two extensions also requesting all privileges possible, despite not actually using them.
    • Two extensions accept messages from any other extension and any Avast website, the latter without enforcing HTTPS connections.
    • One of these extensions, Privacy Guard (sic!), will expose information about your browser’s tabs via that messaging interface and provide updates as you browse the web.
    • The “onboarding” experience is designed as an extremely flexible way to nag you into using products that benefit Avast financially.
    • To make this “onboarding” work, the browser exposes internal APIs to a number of Avast domains that a huge number of third parties can put content on. Not only can each of these third parties abuse this access, a single XSS vulnerability will extend the access to any website on the internet (no effective CSP protection).

    Enjoy!

    #avast #avg #avira #ccleaner #securebrowser #infosec