# The CCleaner affair: the 2017 supply chain attack explained


# The CCleaner affair: the supply chain attack that backdoored 2.27 million PCs

The **CCleaner affair** is one of the textbook cases of a **software supply chain attack**. In August 2017, version 5.33 of the most popular cleaning utility in the world was distributed through official channels with a backdoor grafted inside. Signed with the vendor's genuine certificate, the update infected **2,270,000 computers** in one month, without a single antivirus reacting.

The most troubling part is not the scale of the infection, but its purpose. Behind the operation there was no thief and no blackmailer, but spies. Out of millions of victims, only about forty machines, belonging to giants such as Google, Microsoft, Intel, Cisco or Samsung, received the final payload. The general public was not the target: it was the doorway.

This article retraces the complete timeline of the CCleaner affair, explains how the attack worked technically, revisits the attribution question and details the lessons that durably changed the industry's practices.

{{< admonition abstract "In brief" >}}
- **CCleaner**: two billion downloads, one PC in four worldwide in 2016.
- **11 March 2017**: intrusion at Piriform through TeamViewer, thanks to a reused password.
- **15 August 2017**: release of the trapped version 5.33, signed with the official certificate.
- **2.27 million** infected installs, about **1.6 million** machines that contacted the command server.
- **About forty** targeted machines in some twenty technology companies: industrial espionage.
- **Attribution**: links with the Axiom group, but no certainty and no conviction to this day.
{{< /admonition >}}

{{< youtube oY7TA2fnpxQ >}}

## What is a supply chain attack?

To hit two billion machines, there are two methods. The first is to attack every computer, one by one: impossible at scale. The second is infinitely more elegant, and far more terrifying.

A **supply chain attack** does not target the end user, but the party the user trusts blindly: the software vendor. By compromising the vendor, the attacker turns the official update into a Trojan horse. The mechanism is formidable because it exploits precisely the security reflexes we recommend: keeping software up to date and trusting signed binaries.

{{< admonition info "Supply chain attack, in one sentence" >}}
Rather than forcing millions of locks, the attacker takes over the factory that makes the keys. Every signed update then becomes a perfectly legitimate infection vector in the eyes of the operating system and of antivirus software.
{{< /admonition >}}

## CCleaner before the attack: two billion times trust

To understand the scale of the disaster, you first have to understand the legend. In **2003**, the era of Windows XP, of saturated hard drives and PCs slowing down month after month, a London developer writes a small tool to tidy things up. Its original name, "Crap Cleaner", is soon shortened to **CCleaner**. A year later, the company **Piriform** is founded.

The recipe holds in three words: free, light, effective. The software deletes temporary files, empties caches, cleans the Windows registry and trims startup. Success is immediate:

- **2012**: one billion downloads.
- **2016**: two billion downloads, one for every three people on Earth.
- **Five million** new users every week.

CCleaner is the software you install on your parents' PC and recommend with your eyes closed. A standard, a reflex, a symbol of trust. And that trust is precisely what will be targeted.

## The Avast acquisition and the intrusion at Piriform

In **July 2017**, Avast, the Czech antivirus giant, buys Piriform for an amount later revealed as **121 million dollars**. On paper, it is the perfect match between a security vendor and the most popular cleaning software in the world. But one detail escapes everyone: **at the moment of signing, Piriform's network has already been compromised for four months**. Avast has just bought a booby-trapped company, and Avast itself will soon distribute the poison to the entire world.

### How the attackers got in

On **11 March 2017**, around five in the morning, a Piriform developer's computer was left switched on in the office. The attackers connect to it remotely through a perfectly legitimate tool, **TeamViewer**. A single attempt, successful on the first try, leaving no doubt: they already had the password. A **password reused** by the developer, and leaked in another breach.

Once inside, the attackers move methodically. They hop from one workstation to the next, hide their tools in the corners of the system and, on **12 April 2017**, deploy their most discreet weapon: **ShadowPad**, a modular spyware able to log keystrokes, steal passwords and take remote control. They are not looking to steal a few files. They want the production chain itself.

## Version 5.33: the signed poison

On **15 August 2017**, CCleaner releases version **5.33**. Nothing distinguishes it from dozens of previous updates, except that inside the official file, grafted onto the real program, hides a malware.

The stroke of genius holds in one word: the **signature**. The trapped file is signed with Piriform's genuine digital certificate. Windows checks it, displays "Verified publisher: Piriform" and asks no questions. No antivirus flinches. The poison has its papers in order.

For a month, the infected version is distributed through official channels, downloaded, installed and updated automatically, **2,270,000 times**. On each machine, the malware quietly builds an identity profile, computer name, installed software, network addresses, and sends it to a command and control server. Then it wipes its traces and bides its time.

{{< admonition tip "Flawfence: see what your adversaries see" >}}
This is exactly the kind of invisible threat that pushed us to build [Flawfence](https://flawfence.com), our continuous attack surface assessment platform. It maps what your adversaries see of you: exposed assets, shadow IT, vulnerabilities, continuously and agentically. Because you can only protect what you can see.
{{< /admonition >}}

## Two million victims nobody cared about

And here, the story flips. The two million victims did not interest the attackers. The malware installed on all those PCs was nothing but a giant **fishing net**: it caught everyone, but the attackers were only looking for a few specific fish.

The command server read the domain names of the infected machines and waited for certain companies to show up: **Cisco, Microsoft, Google, Intel, Samsung, Sony, VMware, Vodafone**. On those machines, and those only, a **second payload** was delivered.

| Stage | Machines involved |
|---|---|
| Installs of the infected version 5.33 | 2,270,000 |
| Machines that contacted the command server | about 1,600,000 |
| Machines that received the final payload | around forty, in about twenty companies |

That is **0.0018%** of the victims. This was not a criminal operation, but **industrial espionage**, aimed at stealing the secrets, patents and source code of the technology giants. Cisco Talos' analysts summed it up as "an extremely targeted actor, looking for valuable intellectual property". If your personal PC was infected, you were not the target. You were the doorway to your employer.

## Timeline of detection and response

The attack could have stayed invisible for months. It was betrayed by an anomaly.

| Date | Event |
|---|---|
| Late August 2017 | Security company Morphisec blocks strange CCleaner installations at its customers. |
| 12 September 2017 | Morphisec alerts Avast and Cisco. |
| 13 September 2017 | Cisco Talos researchers find the same thing on their side, almost by accident, while testing a new tool. |
| 15 September 2017 | The attackers' server is taken down, with the help of US authorities. |
| 18 September 2017 | The news goes public. |

A twist complicates the investigation: a few days earlier, the attackers' server had wiped its database for lack of disk space. Investigators first see only a three-day window and about twenty machines. Then a backup is found, and the real scale appears: more than **1.6 million machines**.

### Downplay, then admit

Facing panic, Avast's first reaction is to downplay: "resolved within 72 hours, no known harm, no need to reinstall anything". Cisco Talos publicly contradicts that position: a machine hit by a signed backdoor must be considered compromised and fully reinstalled. A few days later, caught up by the evidence, Avast backtracks and admits the final payload was indeed delivered.

## Who was behind the CCleaner attack?

The day after the disclosure, a Kaspersky researcher notices that the malware's code shares fragments with the tools of the **Axiom** group, a China-linked espionage actor active for years and suspected of targeting Google as early as 2009.

But experts stay cautious: shared code is not proof. The investigation even holds a paradox. The attackers' server was set to the Chinese time zone, while the analysis of connection hours points to Eastern Europe or Central Asia. Two clues, two directions, no certainty.

{{< admonition warning "The attribution problem" >}}
In cybersecurity there are no fingerprints to lift. You assemble a body of presumptions from code, infrastructure, working hours and targets. To this day, nobody has ever been convicted for the CCleaner affair.
{{< /admonition >}}

## CCleaner, a dress rehearsal

CCleaner was not an isolated case, but one of the first episodes of a series that marked the decade:

- The same year, a Ukrainian accounting software was used to trigger **NotPetya**, one of the most destructive cyberattacks in history.
- In **2019**, Avast itself was targeted again, through a forgotten VPN access with no two-factor authentication.
- In **2020**, the **SolarWinds** affair affected up to eighteen thousand organisations.

Always the same principle: compromise a trusted vendor to reach thousands of victims at once. CCleaner was not an anomaly. It was a dress rehearsal.

## How to protect against a supply chain attack

What saved the day in 2017 was not prevention but detection, and a bit of luck. Since then, the industry has changed its practices: hardened build pipelines, distrust by default, verification of every component and dependency. For an organisation, a few concrete measures strongly reduce the risk:

1. **Inventory your software and its updates**, including the "harmless" utilities installed on workstations.
2. **Monitor outbound traffic**: a cleaning utility contacting an unknown server is a detectable anomaly.
3. **Segment the network** so that a compromised workstation does not give access to critical servers.
4. **Demand guarantees from your suppliers** on the security of their build and signing chain.
5. **Test your attack surface regularly**, through [penetration tests](https://trackflaw.com/services) or continuous monitoring such as [Flawfence](https://flawfence.com).

## Frequently asked questions about the CCleaner affair

### Which CCleaner version was infected?

CCleaner version 5.33.6162 for 32-bit Windows, as well as CCleaner Cloud 1.07.3191, distributed between 15 August and 12 September 2017.

### How many computers were hit by the CCleaner malware?

About 2.27 million installs of the trapped version were recorded, and more than 1.6 million machines contacted the command server. Only around forty machines, in some twenty technology companies, received the final espionage payload.

### What should an infected user have done?

Contrary to Avast's first message, Cisco Talos recommended treating the machine as compromised: restoring from a backup predating 15 August 2017 or fully reinstalling the system, then changing passwords.

### Who is responsible for the CCleaner attack?

Attribution is not established with certainty. Code similarities with the tools of the China-linked Axiom group were noted, but timing clues also point to Eastern Europe or Central Asia. Nobody has been convicted.

## Key takeaway: the weakest link was a password

The CCleaner affair was a turning point: the day the general public understood that an official, signed, automatic update could become a weapon, and that trust itself could be hacked.

But remember the detail from the beginning. Everything started with a simple password reused on TeamViewer. Two years later, the second intrusion would start from a VPN with no two-factor authentication. The most sophisticated attack of the decade did not exploit a flaw in the code. The weakest link was not the machine, it was the human.

{{< admonition success "Three habits to keep" >}}
1. **Install your updates**: fast detection remains your best ally, and vendors have massively hardened their build chains since 2017.
2. **Enable two-factor authentication** everywhere you can, starting with remote access (VPN, TeamViewer, RDP).
3. **Never reuse passwords**: a password manager costs less than a backdoor.
{{< /admonition >}}

Because in this story, the door was never forced. Someone had simply left the key under the doormat.

## Sources

- Cisco Talos, [CCleanup: A Vast Number of Machines at Risk](https://blog.talosintelligence.com/avast-distributes-malware/) (2017)
- Cisco Talos, [CCleaner Command and Control Causes Concern](https://blog.talosintelligence.com/ccleaner-c2-concern/) (2017)
- Avast, [Update to the CCleaner 5.33.6162 Security Incident](https://blog.avast.com/update-to-the-ccleaner-5.33.6162-security-incident) (2017)
- Avast, [Additional information regarding the recent CCleaner APT security incident](https://blog.avast.com/additional-information-regarding-the-recent-ccleaner-apt-security-incident) (2017)
- Avast, [New investigations in CCleaner incident point to a possible third stage](https://blog.avast.com/new-investigations-in-ccleaner-incident-point-to-a-possible-third-stage-that-had-keylogger-capacities) (2018)
- Avast, [Attackers entered the Piriform network via TeamViewer](https://blog.avast.com/update-ccleaner-attackers-entered-via-teamviewer) (2018)
- Avast, [CCleaner fights off cyberespionage attempt (Abiss)](https://blog.avast.com/ccleaner-fights-off-cyberespionage-attempt-abiss) (2019)
- Morphisec, [Morphisec Discovers CCleaner Backdoor](https://www.morphisec.com/blog/morphisec-discovers-ccleaner-backdoor/) (2017)
- SecurityWeek, [Backup Database Reveals Scale of CCleaner Hack](https://www.securityweek.com/backup-database-reveals-scale-ccleaner-hack/)
- Wired, [The CCleaner Malware Fiasco Targeted at Least 18 Specific Tech Firms](https://www.wired.com/story/ccleaner-malware-targeted-tech-firms/)
- BleepingComputer, [CCleaner Hack Carried Out to Target Big Tech Companies](https://www.bleepingcomputer.com/news/security/ccleaner-hack-carried-out-in-order-to-target-big-tech-companies/)
- Intezer, [Evidence Aurora Operation Still Active: Supply Chain Attack Through CCleaner](https://intezer.com/blog/evidence-aurora-operation-still-active-supply-chain-attack-through-ccleaner/)
- Kaspersky Securelist, [ShadowPad in corporate networks](https://securelist.com/shadowpad-in-corporate-networks/81432/)
- ESET, [TeleBots are back: supply-chain attacks against Ukraine](https://www.welivesecurity.com/2017/06/30/telebots-back-supply-chain-attacks-against-ukraine/)
- SecurityWeek, [SolarWinds Says 18,000 Customers May Have Used Compromised Product](https://www.securityweek.com/solarwinds-says-18000-customers-may-have-used-compromised-product/)
- Piriform, [2 Billion CCleaner Downloads Worldwide](https://newsroom.gendigital.com/2016-11-03-piriform-announces-2-billion-ccleaner-downloads-worldwide) (2016)
- Avast, [Avast acquires Piriform, maker of CCleaner](https://newsroom.gendigital.com/2017-07-19-Avast-acquires-Piriform,-maker-of-CCleaner) (2017)

