#ccleaner — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #ccleaner, aggregated by home.social.
-
🚨 Fake #CCleaner installs GhostDesk spyware
The trojanized installer deploys Chrome-focused spyware to steal browser data.
🔗 read more: www.malwarebytes.com...
#ransomNews #cybersecurity
Fake CCleaner installs GhostDe... -
Fake CCleaner installs GhostDesk Chrome spyware
Pulse ID: 6a7d498dc95702116f348241
Pulse Link: https://otx.alienvault.com/pulse/6a7d498dc95702116f348241
Pulse Author: Tr1sa111
Created: 2026-08-13 04:35:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CCleaner #Chrome #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #bot #Tr1sa111
-
Fake CCleaner installs GhostDesk Chrome spyware
Pulse ID: 6a7d498dc95702116f348241
Pulse Link: https://otx.alienvault.com/pulse/6a7d498dc95702116f348241
Pulse Author: Tr1sa111
Created: 2026-08-13 04:35:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CCleaner #Chrome #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #bot #Tr1sa111
-
Fake CCleaner installs GhostDesk Chrome spyware
Pulse ID: 6a7d498dc95702116f348241
Pulse Link: https://otx.alienvault.com/pulse/6a7d498dc95702116f348241
Pulse Author: Tr1sa111
Created: 2026-08-13 04:35:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CCleaner #Chrome #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #bot #Tr1sa111
-
Fake CCleaner installs GhostDesk Chrome spyware
Pulse ID: 6a7d498dc95702116f348241
Pulse Link: https://otx.alienvault.com/pulse/6a7d498dc95702116f348241
Pulse Author: Tr1sa111
Created: 2026-08-13 04:35:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CCleaner #Chrome #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #bot #Tr1sa111
-
Fake CCleaner installs GhostDesk Chrome spyware
Pulse ID: 6a7d498dc95702116f348241
Pulse Link: https://otx.alienvault.com/pulse/6a7d498dc95702116f348241
Pulse Author: Tr1sa111
Created: 2026-08-13 04:35:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CCleaner #Chrome #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #bot #Tr1sa111
-
Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs
Indicators extracted from public reporting. Source: https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware
Pulse ID: 6a7c6d5cf70eca6997f0ff3b
Pulse Link: https://otx.alienvault.com/pulse/6a7c6d5cf70eca6997f0ff3b
Pulse Author: CyberHunter_NL
Created: 2026-08-12 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #Windows #bot #CyberHunter_NL
-
Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs
Indicators extracted from public reporting. Source: https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware
Pulse ID: 6a7c6d5cf70eca6997f0ff3b
Pulse Link: https://otx.alienvault.com/pulse/6a7c6d5cf70eca6997f0ff3b
Pulse Author: CyberHunter_NL
Created: 2026-08-12 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #Windows #bot #CyberHunter_NL
-
Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs
Indicators extracted from public reporting. Source: https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware
Pulse ID: 6a7c6d5cf70eca6997f0ff3b
Pulse Link: https://otx.alienvault.com/pulse/6a7c6d5cf70eca6997f0ff3b
Pulse Author: CyberHunter_NL
Created: 2026-08-12 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #Windows #bot #CyberHunter_NL
-
Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs
Indicators extracted from public reporting. Source: https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware
Pulse ID: 6a7c6d5cf70eca6997f0ff3b
Pulse Link: https://otx.alienvault.com/pulse/6a7c6d5cf70eca6997f0ff3b
Pulse Author: CyberHunter_NL
Created: 2026-08-12 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #Windows #bot #CyberHunter_NL
-
Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs
Indicators extracted from public reporting. Source: https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware
Pulse ID: 6a7c6d5cf70eca6997f0ff3b
Pulse Link: https://otx.alienvault.com/pulse/6a7c6d5cf70eca6997f0ff3b
Pulse Author: CyberHunter_NL
Created: 2026-08-12 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #Windows #bot #CyberHunter_NL
-
Fake CCleaner installs GhostDesk Chrome spyware
A fraudulent version of the widely-used PC cleaning utility CCleaner is being distributed through a convincing imitation website to deploy GhostDesk, a malicious Chrome extension functioning as spyware. The attack begins when users download the fake application from a lookalike site, which then launches a multi-stage infection using CScript to modify Chrome's Security Extension and install malicious components. Once active, GhostDesk performs extensive surveillance including credential theft, keylogging, screenshot capture, cookie harvesting, and cryptojacking. The extension establishes command-and-control communications via WebSocket connections and can execute arbitrary code within browser tabs. Similar fake versions of other popular software like 7-Zip and Adobe Acrobat have been identified using identical infection techniques.
Pulse ID: 6a7b8dab529ad28b12d29796
Pulse Link: https://otx.alienvault.com/pulse/6a7b8dab529ad28b12d29796
Pulse Author: AlienVault
Created: 2026-08-11 21:01:31Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #Browser #CCleaner #Chrome #ChromeExtension #CryptoJacking #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #ZIP #bot #AlienVault
-
Fake CCleaner installs GhostDesk Chrome spyware
A fraudulent version of the widely-used PC cleaning utility CCleaner is being distributed through a convincing imitation website to deploy GhostDesk, a malicious Chrome extension functioning as spyware. The attack begins when users download the fake application from a lookalike site, which then launches a multi-stage infection using CScript to modify Chrome's Security Extension and install malicious components. Once active, GhostDesk performs extensive surveillance including credential theft, keylogging, screenshot capture, cookie harvesting, and cryptojacking. The extension establishes command-and-control communications via WebSocket connections and can execute arbitrary code within browser tabs. Similar fake versions of other popular software like 7-Zip and Adobe Acrobat have been identified using identical infection techniques.
Pulse ID: 6a7b8dab529ad28b12d29796
Pulse Link: https://otx.alienvault.com/pulse/6a7b8dab529ad28b12d29796
Pulse Author: AlienVault
Created: 2026-08-11 21:01:31Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #Browser #CCleaner #Chrome #ChromeExtension #CryptoJacking #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #ZIP #bot #AlienVault
-
Fake CCleaner installs GhostDesk Chrome spyware
A fraudulent version of the widely-used PC cleaning utility CCleaner is being distributed through a convincing imitation website to deploy GhostDesk, a malicious Chrome extension functioning as spyware. The attack begins when users download the fake application from a lookalike site, which then launches a multi-stage infection using CScript to modify Chrome's Security Extension and install malicious components. Once active, GhostDesk performs extensive surveillance including credential theft, keylogging, screenshot capture, cookie harvesting, and cryptojacking. The extension establishes command-and-control communications via WebSocket connections and can execute arbitrary code within browser tabs. Similar fake versions of other popular software like 7-Zip and Adobe Acrobat have been identified using identical infection techniques.
Pulse ID: 6a7b8dab529ad28b12d29796
Pulse Link: https://otx.alienvault.com/pulse/6a7b8dab529ad28b12d29796
Pulse Author: AlienVault
Created: 2026-08-11 21:01:31Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #Browser #CCleaner #Chrome #ChromeExtension #CryptoJacking #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #ZIP #bot #AlienVault
-
Fake CCleaner installs GhostDesk Chrome spyware
A fraudulent version of the widely-used PC cleaning utility CCleaner is being distributed through a convincing imitation website to deploy GhostDesk, a malicious Chrome extension functioning as spyware. The attack begins when users download the fake application from a lookalike site, which then launches a multi-stage infection using CScript to modify Chrome's Security Extension and install malicious components. Once active, GhostDesk performs extensive surveillance including credential theft, keylogging, screenshot capture, cookie harvesting, and cryptojacking. The extension establishes command-and-control communications via WebSocket connections and can execute arbitrary code within browser tabs. Similar fake versions of other popular software like 7-Zip and Adobe Acrobat have been identified using identical infection techniques.
Pulse ID: 6a7b8dab529ad28b12d29796
Pulse Link: https://otx.alienvault.com/pulse/6a7b8dab529ad28b12d29796
Pulse Author: AlienVault
Created: 2026-08-11 21:01:31Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #Browser #CCleaner #Chrome #ChromeExtension #CryptoJacking #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #ZIP #bot #AlienVault
-
Fake CCleaner installs GhostDesk Chrome spyware
A fraudulent version of the widely-used PC cleaning utility CCleaner is being distributed through a convincing imitation website to deploy GhostDesk, a malicious Chrome extension functioning as spyware. The attack begins when users download the fake application from a lookalike site, which then launches a multi-stage infection using CScript to modify Chrome's Security Extension and install malicious components. Once active, GhostDesk performs extensive surveillance including credential theft, keylogging, screenshot capture, cookie harvesting, and cryptojacking. The extension establishes command-and-control communications via WebSocket connections and can execute arbitrary code within browser tabs. Similar fake versions of other popular software like 7-Zip and Adobe Acrobat have been identified using identical infection techniques.
Pulse ID: 6a7b8dab529ad28b12d29796
Pulse Link: https://otx.alienvault.com/pulse/6a7b8dab529ad28b12d29796
Pulse Author: AlienVault
Created: 2026-08-11 21:01:31Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #Browser #CCleaner #Chrome #ChromeExtension #CryptoJacking #CyberSecurity #InfoSec #OTX #OpenThreatExchange #SpyWare #ZIP #bot #AlienVault
-
Fake CCleaner installs GhostDesk Chrome spyware
Indicators extracted from public reporting. Source: https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware
Pulse ID: 6a7b8c83bf51f40e5a39c8e5
Pulse Link: https://otx.alienvault.com/pulse/6a7b8c83bf51f40e5a39c8e5
Pulse Author: CyberHunter_NL
Created: 2026-08-11 20:56:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #bot #CyberHunter_NL
-
Fake CCleaner installs GhostDesk Chrome spyware
Indicators extracted from public reporting. Source: https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware
Pulse ID: 6a7b8c83bf51f40e5a39c8e5
Pulse Link: https://otx.alienvault.com/pulse/6a7b8c83bf51f40e5a39c8e5
Pulse Author: CyberHunter_NL
Created: 2026-08-11 20:56:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #bot #CyberHunter_NL
-
Fake CCleaner installs GhostDesk Chrome spyware
Indicators extracted from public reporting. Source: https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware
Pulse ID: 6a7b8c83bf51f40e5a39c8e5
Pulse Link: https://otx.alienvault.com/pulse/6a7b8c83bf51f40e5a39c8e5
Pulse Author: CyberHunter_NL
Created: 2026-08-11 20:56:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #bot #CyberHunter_NL
-
Fake CCleaner installs GhostDesk Chrome spyware
Indicators extracted from public reporting. Source: https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware
Pulse ID: 6a7b8c83bf51f40e5a39c8e5
Pulse Link: https://otx.alienvault.com/pulse/6a7b8c83bf51f40e5a39c8e5
Pulse Author: CyberHunter_NL
Created: 2026-08-11 20:56:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #bot #CyberHunter_NL
-
Fake CCleaner installs GhostDesk Chrome spyware
Indicators extracted from public reporting. Source: https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware
Pulse ID: 6a7b8c83bf51f40e5a39c8e5
Pulse Link: https://otx.alienvault.com/pulse/6a7b8c83bf51f40e5a39c8e5
Pulse Author: CyberHunter_NL
Created: 2026-08-11 20:56:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #bot #CyberHunter_NL
-
Learn why CCleaner is useless on Linux and macOS and the 5 commands you actually need to keep your Linux system clean, plus what macOS users should do instead.
Full guide here: https://ostechnix.com/ccleaner-is-useless-on-linux-and-macos/
-
Learn why CCleaner is useless on Linux and macOS and the 5 commands you actually need to keep your Linux system clean, plus what macOS users should do instead.
Full guide here: https://ostechnix.com/ccleaner-is-useless-on-linux-and-macos/
-
Learn why CCleaner is useless on Linux and macOS and the 5 commands you actually need to keep your Linux system clean, plus what macOS users should do instead.
Full guide here: https://ostechnix.com/ccleaner-is-useless-on-linux-and-macos/
-
Learn why CCleaner is useless on Linux and macOS and the 5 commands you actually need to keep your Linux system clean, plus what macOS users should do instead.
Full guide here: https://ostechnix.com/ccleaner-is-useless-on-linux-and-macos/
-
Learn why CCleaner is useless on Linux and macOS and the 5 commands you actually need to keep your Linux system clean, plus what macOS users should do instead.
Full guide here: https://ostechnix.com/ccleaner-is-useless-on-linux-and-macos/
-
"I stopped using #CCleaner and #Windows tools did the same job"
What finally changed wasn’t CCleaner itself, but Windows. As the operating system matured, it started taking over the same #cleanup tasks that once required a third-party tool.
#StorageSense handles everyday cleanup
Settings -> System -> Storage
https://www.makeuseof.com/i-stopped-using-ccleaner-and-windows-tools-did-the-same-job/
-
"I stopped using #CCleaner and #Windows tools did the same job"
What finally changed wasn’t CCleaner itself, but Windows. As the operating system matured, it started taking over the same #cleanup tasks that once required a third-party tool.
#StorageSense handles everyday cleanup
Settings -> System -> Storage
https://www.makeuseof.com/i-stopped-using-ccleaner-and-windows-tools-did-the-same-job/
-
"I stopped using #CCleaner and #Windows tools did the same job"
What finally changed wasn’t CCleaner itself, but Windows. As the operating system matured, it started taking over the same #cleanup tasks that once required a third-party tool.
#StorageSense handles everyday cleanup
Settings -> System -> Storage
https://www.makeuseof.com/i-stopped-using-ccleaner-and-windows-tools-did-the-same-job/
-
"I stopped using #CCleaner and #Windows tools did the same job"
What finally changed wasn’t CCleaner itself, but Windows. As the operating system matured, it started taking over the same #cleanup tasks that once required a third-party tool.
#StorageSense handles everyday cleanup
Settings -> System -> Storage
https://www.makeuseof.com/i-stopped-using-ccleaner-and-windows-tools-did-the-same-job/
-
"I stopped using #CCleaner and #Windows tools did the same job"
What finally changed wasn’t CCleaner itself, but Windows. As the operating system matured, it started taking over the same #cleanup tasks that once required a third-party tool.
#StorageSense handles everyday cleanup
Settings -> System -> Storage
https://www.makeuseof.com/i-stopped-using-ccleaner-and-windows-tools-did-the-same-job/
-
-
La #merdification du jour : #CCleaner, dont la dernière version fait passer certaines fonctions en mode payant. Et impossible de rester sur une ancienne version : il semble que la mise à jour vers la dernière est forcée par le logiciel.
Bah, vous me direz : ces “utilitaires” ont toujours fait plus de mal que de bien à Windows, donc raison de plus pour les dégager et ne jamais les installer ! 🚮
-
La #merdification du jour : #CCleaner, dont la dernière version fait passer certaines fonctions en mode payant. Et impossible de rester sur une ancienne version : il semble que la mise à jour vers la dernière est forcée par le logiciel.
Bah, vous me direz : ces “utilitaires” ont toujours fait plus de mal que de bien à Windows, donc raison de plus pour les dégager et ne jamais les installer ! 🚮
-
La #merdification du jour : #CCleaner, dont la dernière version fait passer certaines fonctions en mode payant. Et impossible de rester sur une ancienne version : il semble que la mise à jour vers la dernière est forcée par le logiciel.
Bah, vous me direz : ces “utilitaires” ont toujours fait plus de mal que de bien à Windows, donc raison de plus pour les dégager et ne jamais les installer ! 🚮
-
La #merdification du jour : #CCleaner, dont la dernière version fait passer certaines fonctions en mode payant. Et impossible de rester sur une ancienne version : il semble que la mise à jour vers la dernière est forcée par le logiciel.
Bah, vous me direz : ces “utilitaires” ont toujours fait plus de mal que de bien à Windows, donc raison de plus pour les dégager et ne jamais les installer ! 🚮
-
#CCleaner war ein nettes, kostenloses Programm zur Bereinigung der Cache-Speicher und der Registry. Dann wurde es von Avast gekauft. Zuerst wurden nervigen Popups für kostenpflichtigen Dreck eingeführt und nun haben sie die ursprüngliche Grundfunktion des Programms verhunzt. Schade! 🙄
-
#CCleaner war ein nettes, kostenloses Programm zur Bereinigung der Cache-Speicher und der Registry. Dann wurde es von Avast gekauft. Zuerst wurden nervigen Popups für kostenpflichtigen Dreck eingeführt und nun haben sie die ursprüngliche Grundfunktion des Programms verhunzt. Schade! 🙄
-
#CCleaner war ein nettes, kostenloses Programm zur Bereinigung der Cache-Speicher und der Registry. Dann wurde es von Avast gekauft. Zuerst wurden nervigen Popups für kostenpflichtigen Dreck eingeführt und nun haben sie die ursprüngliche Grundfunktion des Programms verhunzt. Schade! 🙄
-
Bilgisayarı Yavaşlatan Programları Tespit Etme Yöntemleri
#bilgisayarkontrolü, #performans, #görevYöneticisi, #başlangıçprogramları, #disktemizliği, #optimizasyon, #ccleaner, #sistembakımı, #yavaşbilgisayar, #verimlilik
https://huseyinozbekar.com/bilgisayari-yavaslatan-programlari-tespit-etme-yontemleri/
-
#メモ #CCleaner #バグ
CCleaner はコンピュータをより速く、より安全に | 公式ウェブサイト
https://www.ccleaner.com/ja-jp書き込みエラーでアップデートできなかった。
-
Lleva un tiempecito, pero ahí va.
Nueva #actualizacion de #Bleachbit con mejoras de seguridad y reconocimiento y limpieza de más programas.
Configuradlo con cuidado si no queréis perder algún ajuste o sesión de navegador, ya que esto limpia a conciencia y debe usarse igual de concienzudamente.
Si no conoces este programa y sigues usando #CCleaner aun estás a tiempo de salir de la edad de piedra. Pruébalo y verás la diferencia. -
Lleva un tiempecito, pero ahí va.
Nueva #actualizacion de #Bleachbit con mejoras de seguridad y reconocimiento y limpieza de más programas.
Configuradlo con cuidado si no queréis perder algún ajuste o sesión de navegador, ya que esto limpia a conciencia y debe usarse igual de concienzudamente.
Si no conoces este programa y sigues usando #CCleaner aun estás a tiempo de salir de la edad de piedra. Pruébalo y verás la diferencia. -
Lleva un tiempecito, pero ahí va.
Nueva #actualizacion de #Bleachbit con mejoras de seguridad y reconocimiento y limpieza de más programas.
Configuradlo con cuidado si no queréis perder algún ajuste o sesión de navegador, ya que esto limpia a conciencia y debe usarse igual de concienzudamente.
Si no conoces este programa y sigues usando #CCleaner aun estás a tiempo de salir de la edad de piedra. Pruébalo y verás la diferencia. -
Lleva un tiempecito, pero ahí va.
Nueva #actualizacion de #Bleachbit con mejoras de seguridad y reconocimiento y limpieza de más programas.
Configuradlo con cuidado si no queréis perder algún ajuste o sesión de navegador, ya que esto limpia a conciencia y debe usarse igual de concienzudamente.
Si no conoces este programa y sigues usando #CCleaner aun estás a tiempo de salir de la edad de piedra. Pruébalo y verás la diferencia. -
Just had a message saying I needed to update #Ccleaner. Looked suspicious, because doesn’t Ccleaner update itself? Opened the program, and it says I am using the latest edition. Suspicion: this wasn’t from the web, but Ccleaner purposely confusing the words update and upgrade, tricking users into paying.
-
Just had a message saying I needed to update #Ccleaner. Looked suspicious, because doesn’t Ccleaner update itself? Opened the program, and it says I am using the latest edition. Suspicion: this wasn’t from the web, but Ccleaner purposely confusing the words update and upgrade, tricking users into paying.
-
Just had a message saying I needed to update #Ccleaner. Looked suspicious, because doesn’t Ccleaner update itself? Opened the program, and it says I am using the latest edition. Suspicion: this wasn’t from the web, but Ccleaner purposely confusing the words update and upgrade, tricking users into paying.
-
Just had a message saying I needed to update #Ccleaner. Looked suspicious, because doesn’t Ccleaner update itself? Opened the program, and it says I am using the latest edition. Suspicion: this wasn’t from the web, but Ccleaner purposely confusing the words update and upgrade, tricking users into paying.
-
Just had a message saying I needed to update #Ccleaner. Looked suspicious, because doesn’t Ccleaner update itself? Opened the program, and it says I am using the latest edition. Suspicion: this wasn’t from the web, but Ccleaner purposely confusing the words update and upgrade, tricking users into paying.
-
Подельники или подражатели? Подробности атак группировки PhaseShifters
С весны 2023 года мы активно наблюдаем за одной любопытной группировкой. Мы назвали ее PhaseShifters, так как заметили, что она меняет свои техники вслед за другим группировками, например UAC-0050 и TA558. В своих атаках PhaseShifters используют фишинг от имени официальных лиц с просьбой ознакомиться с документами и их подписать. А эти документы, в свою очередь, защищены паролем и (что предсказуемо) заражены. В качестве ВПО злоумышленники используют Rhadamanthys, DarkTrack RAT, Meta Stealer — часть этих инструментов мы заметили у UAC-0050. А использованные криптеры были те же, что и у группировок TA558 и Blind Eagle. Кто у кого списал?
https://habr.com/ru/companies/pt/articles/855382/
#apt #cybersecurity #вредоносное_по #ccleaner #стеганография #расследование #кибергруппировки #bitbucket #darktrack_rat
-
Подельники или подражатели? Подробности атак группировки PhaseShifters
С весны 2023 года мы активно наблюдаем за одной любопытной группировкой. Мы назвали ее PhaseShifters, так как заметили, что она меняет свои техники вслед за другим группировками, например UAC-0050 и TA558. В своих атаках PhaseShifters используют фишинг от имени официальных лиц с просьбой ознакомиться с документами и их подписать. А эти документы, в свою очередь, защищены паролем и (что предсказуемо) заражены. В качестве ВПО злоумышленники используют Rhadamanthys, DarkTrack RAT, Meta Stealer — часть этих инструментов мы заметили у UAC-0050. А использованные криптеры были те же, что и у группировок TA558 и Blind Eagle. Кто у кого списал?
https://habr.com/ru/companies/pt/articles/855382/
#apt #cybersecurity #вредоносное_по #ccleaner #стеганография #расследование #кибергруппировки #bitbucket #darktrack_rat
-
Подельники или подражатели? Подробности атак группировки PhaseShifters
С весны 2023 года мы активно наблюдаем за одной любопытной группировкой. Мы назвали ее PhaseShifters, так как заметили, что она меняет свои техники вслед за другим группировками, например UAC-0050 и TA558. В своих атаках PhaseShifters используют фишинг от имени официальных лиц с просьбой ознакомиться с документами и их подписать. А эти документы, в свою очередь, защищены паролем и (что предсказуемо) заражены. В качестве ВПО злоумышленники используют Rhadamanthys, DarkTrack RAT, Meta Stealer — часть этих инструментов мы заметили у UAC-0050. А использованные криптеры были те же, что и у группировок TA558 и Blind Eagle. Кто у кого списал?
https://habr.com/ru/companies/pt/articles/855382/
#apt #cybersecurity #вредоносное_по #ccleaner #стеганография #расследование #кибергруппировки #bitbucket #darktrack_rat
-
CCleanerのバグらしき動作。もしかしたら、#Firefox でもよく起こる。アイコンなどの表示の失敗が起こっていたのかもしれない。気づかなかったけれど…。昔はアイコンに画像ファイル的なものが使われていたのだけど、最近は何らかのコードを変換して画像にするようなことが多く、#Outlookでは、その読み込みというか表示に失敗して延々と読み込み中になることがある。それと同じようなことが #CCleaner でも起こっていたのかもしれない。
-
It has been a while since I’ve written about Avast, so today I give you “How insecure is Avast Secure Browser?”
https://palant.info/2024/07/15/how-insecure-is-avast-secure-browser/
Note: This isn’t a vulnerability disclosure, merely an overview of problematic design decisions.
TL;DR from the article: I wouldn’t run Avast Secure Browser on any real operating system, only inside a virtual machine containing no data whatsoever.
Some highlights:
- Eleven pre-installed browser extensions but only two visible to users.
- Two extensions unnecessarily relax Content-Security-Policy protection.
- One of these two extensions also requesting all privileges possible, despite not actually using them.
- Two extensions accept messages from any other extension and any Avast website, the latter without enforcing HTTPS connections.
- One of these extensions, Privacy Guard (sic!), will expose information about your browser’s tabs via that messaging interface and provide updates as you browse the web.
- The “onboarding” experience is designed as an extremely flexible way to nag you into using products that benefit Avast financially.
- To make this “onboarding” work, the browser exposes internal APIs to a number of Avast domains that a huge number of third parties can put content on. Not only can each of these third parties abuse this access, a single XSS vulnerability will extend the access to any website on the internet (no effective CSP protection).
Enjoy!
-
It has been a while since I’ve written about Avast, so today I give you “How insecure is Avast Secure Browser?”
https://palant.info/2024/07/15/how-insecure-is-avast-secure-browser/
Note: This isn’t a vulnerability disclosure, merely an overview of problematic design decisions.
TL;DR from the article: I wouldn’t run Avast Secure Browser on any real operating system, only inside a virtual machine containing no data whatsoever.
Some highlights:
- Eleven pre-installed browser extensions but only two visible to users.
- Two extensions unnecessarily relax Content-Security-Policy protection.
- One of these two extensions also requesting all privileges possible, despite not actually using them.
- Two extensions accept messages from any other extension and any Avast website, the latter without enforcing HTTPS connections.
- One of these extensions, Privacy Guard (sic!), will expose information about your browser’s tabs via that messaging interface and provide updates as you browse the web.
- The “onboarding” experience is designed as an extremely flexible way to nag you into using products that benefit Avast financially.
- To make this “onboarding” work, the browser exposes internal APIs to a number of Avast domains that a huge number of third parties can put content on. Not only can each of these third parties abuse this access, a single XSS vulnerability will extend the access to any website on the internet (no effective CSP protection).
Enjoy!
-
It has been a while since I’ve written about Avast, so today I give you “How insecure is Avast Secure Browser?”
https://palant.info/2024/07/15/how-insecure-is-avast-secure-browser/
Note: This isn’t a vulnerability disclosure, merely an overview of problematic design decisions.
TL;DR from the article: I wouldn’t run Avast Secure Browser on any real operating system, only inside a virtual machine containing no data whatsoever.
Some highlights:
- Eleven pre-installed browser extensions but only two visible to users.
- Two extensions unnecessarily relax Content-Security-Policy protection.
- One of these two extensions also requesting all privileges possible, despite not actually using them.
- Two extensions accept messages from any other extension and any Avast website, the latter without enforcing HTTPS connections.
- One of these extensions, Privacy Guard (sic!), will expose information about your browser’s tabs via that messaging interface and provide updates as you browse the web.
- The “onboarding” experience is designed as an extremely flexible way to nag you into using products that benefit Avast financially.
- To make this “onboarding” work, the browser exposes internal APIs to a number of Avast domains that a huge number of third parties can put content on. Not only can each of these third parties abuse this access, a single XSS vulnerability will extend the access to any website on the internet (no effective CSP protection).
Enjoy!