AfterDawn: Tech news

Avast prevents attack targeting CCleaner

Written by James Delahunty @ 23 Oct 2019 12:27

Avast prevents attack targeting CCleaner Avast has detailed how it prevented a suspected supply chain attack on the popular CCleaner software product.
CCleaner had been targeted in such an attack in 2017 and led to Piriform unknowingly distributing malware with the installer for the better part of a month. Attackers had successfully breached the development environment and made malicious modifications before distribution.

Avast has confirmed that it has prevented a similar incident from occurring. It has detailed "Abiss" in a blog post; a suspected supply chain attack on the CCleaner product. The most important detail is that the attempt was unsuccessful and no users of the product were exposed to malware as a result.

The clues that something was amiss started with a false positive in the form of a MS ATA alert of a malicious replication of directory services from an internal IP belonged to Avast's VPN address range. Further analysis found the attacker was attempting to gain access to the network through the VPN as early as May 14, 2019.



The user, whose credentials were apparently compromised and associated with the IP, did not have domain admin privileges. However, the attacker managed to gain domain admin privileges through a successful privilege investigation.

Avast determined that its internal network was accessed with compromised credentials through a temporary VPN profile that had erroneously been kept enabled. It didn't require two-factor authentication. According to the logs, the temporary profile had been used by multiple sets of user credentials. Avast believes that they were all subject to credential theft.

Instead of shutting down the temporary VPN profile, Avast left it open so it could monitor the actor's activities. It was working with Security Information Services (BIS), which is the Czech intelligence service, and also an external forensics team. While it kept an eye on the malicious activity, it halted upcoming CCleaner releases on September 25 and verified no malicious alterations were made to previous updates.

To be safe, it re-signed a clean update of the product, pushed it out to users via an automatic update on October 15, and then revoked the previous certificate. It then closed the temporary VPN profile as the newly signed build of CCleaner would alert the attacker.

"From the insights we have gathered so far, it is clear that this was an extremely sophisticated attempt against us that had the intention to leave no traces of the intruder or their purpose, and that the actor was progressing with exceptional caution in order to not be detected," Jaya Baloo writes on the Avast blog.

"We do not know if this was the same actor as before and it is likely we will never know for sure, so we have named this attempt 'Abiss'.!"

Read the full post at blog.avast.com

Tags: CCleaner Avast
Previous Next  
Comments have been disabled for this article.

Latest news

VLC hits milestone: over 5 billion downloads VLC hits milestone: over 5 billion downloads (16 Mar 2024 4:31)
VLC Media Player, the versatile video-software powerhouse, has achieved a remarkable feat: it has been downloaded over 5 billion times.
1 user comment
Sideloading apps to Android gets easier, as Google settles its lawsuit Sideloading apps to Android gets easier, as Google settles its lawsuit (19 Dec 2023 11:09)
Google settled its lawsuit in September 2023, and one of the settlement terms was that the way applications are installed on Android from outside the Google Play Store must become simpler. In the future, installing APK files will be easier.
8 user comments
Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets (06 Jun 2023 9:19)
Roomba Combo j7+ is the very first Roomba model to combine robot vacuum with mopping features. And Roomba Combo j7+ does all that with a very clever trick, which tackles the problem with mopping and carpets. But is it any good? We found out.
Neato, the robot vacuum company, ends its operations Neato, the robot vacuum company, ends its operations (02 May 2023 3:38)
Neato Robotics has ceased its operations. American robot vacuum pioneer founded in 2005 has finally called it quits and company will cease its operations and sales. Only a skeleton crew will remain who will keep the servers running until 2028.
5 user comments
How to Send Messages to Yourself on WhatsApp How to Send Messages to Yourself on WhatsApp (20 Mar 2023 1:25)
The world's most popular messaging platform, Meta-owned WhatsApp has enabled sending messages to yourself. While at first, this might seem like an odd feature, it can be very useful in a lot of situations. ....
18 user comments

News archive