Researchers: CCleaner attack aimed at major tech companies – CNET

Hackers

CCleaner is downloaded millions of times a week for free.

Sergei Konkov

At first it seemed like the hacking campaign against users of popular software CCleaner hadn’t been able to do much damage. Well, not so fast.

Researchers now say the hackers were able to install a second piece of malicious software on computers at major tech companies around the world. The companies targeted include heavyweights such as Microsoft, Google, Samsung, Sony and Intel, according to the Talos threat intelligence team, a group of cybersecurity experts at Cisco. Also on the list of targeted companies? Cisco itself.

The targets represent many of the most important companies responsible for making the internet work, making the hacking attack much more serious.

vCard QR Code

vCard.red is a free platform for creating a mobile-friendly digital business cards. You can easily create a vCard and generate a QR code for it, allowing others to scan and save your contact details instantly.

The platform allows you to display contact information, social media links, services, and products all in one shareable link. Optional features include appointment scheduling, WhatsApp-based storefronts, media galleries, and custom design options.

News of the hacking attack broke Monday, when Talos and Avast each announced that hackers had inserted malicious software into legitimate updates of CCleaner, a product that clears out unneeded software applications and cookies from PCs to make them run more efficiently. Even though 2.27 million computers were potentially exposed to the software, both Avast and Talos said Monday it seemed the attackers hadn’t used the malware to do any damage.

Now it seems that first wave of malware was just the beginning, opening a secret back door into all those computers. On a select set of valuable computers at major tech companies, the hackers used the back door to install even more malicious software.

Talos researchers don’t know yet what the hackers hoped to do once they dug further into computers at these companies, but it’s clear there was potential to do damage. In short, these hackers meant business.

“This would suggest a very focused actor after valuable intellectual property,” the Talos researchers wrote in their blog post.

The Talos team published its findings in a blog post Wednesday evening. Cybersecurity firm Avast, which in July purchased the company that provides CCleaner, said in a blog post Thursday it had come to a similar conclusion. According to Avast’s analysis, it knows for sure that 18 computers at eight different organizations were hit with the second wave of malicious software. What’s more, because it only has a small slice of data to examine, Avast said it thinks the total number of affected computers is probably “at least in the order of hundreds.”

However, Avast declined to name any of the companies targeted. It’s unclear if any or all of the companies named in the Talos blog post were actually among the eight companies Avast says were hit by the second wave of malicious software.

Google and Intel declined to comment, and representatives from Sony and Samsung didn’t respond to requests for comment.

“It’s expected that security researchers will perform forensic analysis of new malware, and it is not a surprise that malware sometimes targets specific companies,” Microsoft said in a statement.

Talos researchers also named D-Link, Linksys, HTC and Akamai as targets of the hackers. Representatives of D-Link and Linksys didn’t respond to a request for comment. 

“A small number of our client systems downloaded the malicious software from Avast,” Akamai spokesman Robert Morton said in an email. “We are in the process of examining these systems, but we have seen no evidence to date of the secondary payload or C2 channel on any of the affected systems.”

An HTC spokesman said a web domain listed by the researchers, HTCgroup.corp, was not registered to the company and that HTC doesn’t go by the name HTC group.

“These are all critical infrastructure vendors here,” said Tod Beardsley, a cybersecurity forensics expert at Rapid7, who was not involved in the research. The list of targets includes, he said, “all the operating systems and routers that anyone cares about.”

CNET Magazine: Check out a sample of the stories in CNET’s newsstand edition.

The Smartest Stuff: Innovators are thinking up new ways to make you, and the things around you, smarter.


🕐 Top News in the Last Hour By Importance Score

# Title 📊 i-Score
1 Chinese garment factories that supply Shein shut down amid Trump tariffs: ‘There are only risks to doing business with the US now’ 🔴 75 / 100
2 When Did Pope Francis Become Pope? Look Back on His Papacy 🔴 72 / 100
3 ‘Full-blown meltdown’ at Pentagon after Pete Hegseth’s second Signal chat revealed 🔴 65 / 100
4 Lisa Rinna reveals heartbreaking reason she threatened to kill husband Harry Hamlin 🔴 62 / 100
5 Tesla reportedly delays launch of new low-cost model by months 🔴 62 / 100
6 Padres star Luis Arraez breaks his silence from hospital bed after sickening collision left him out cold 🔵 55 / 100
7 Football matches CALLED OFF in Italy after Pope Franics dies aged 88 as pontiff's passing plunges Catholics into mourning 🔵 55 / 100
8 Tim Spector warns people who bloat to stop night-time habit 🔵 45 / 100
9 Phil Jackson blasts NBA for decision that violates 'sacred days' in rare post 🔵 45 / 100
10 'Best TV series' on Netflix leaves fans saying 'absolute must see' 🔵 40 / 100

View More Top News ➡️