CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◇ Industry News & Leadership Aug 12, 2026

Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs

Cybersecurity News Archived Aug 12, 2026 ✓ Full text saved

Windows users looking for a familiar cleanup utility are being steered toward a convincing counterfeit download page. The file they receive installs GhostDesk, a malicious Chrome extension built to watch activity inside the browser. The campaign turns a routine software download into a pathway for credential theft, keystroke capture, screenshots, cookie collection, and commands delivered […] The post Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs appeared first on Cyber

Full text archived locally
✦ AI Summary · Claude Sonnet


    HomeCyber Security News Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs By Tushar Subhra Dutta August 12, 2026 Windows users looking for a familiar cleanup utility are being steered toward a convincing counterfeit download page. The file they receive installs GhostDesk, a malicious Chrome extension built to watch activity inside the browser. The campaign turns a routine software download into a pathway for credential theft, keystroke capture, screenshots, cookie collection, and commands delivered to browser tabs. Its use of a trusted application name shows why a polished page and familiar icon cannot establish that a download is safe. Malwarebytes said in a report shared with Cyber Security News (CSN) that the operation begins with a fake CCleaner site and proceeds through a multi-stage Windows infection. The researchers found the lure at ccleanerwind[.]top, where both displayed download choices served the same harmful executable. The immediate impact is potentially serious for anyone who uses Chrome for email, banking, work portals, or cryptocurrency services. Fake application (Source – Malwarebytes) Unlike a noisy pop-up campaign, GhostDesk is designed to run in the background, leaving victims unaware that browser data may be exposed. Fake CCleaner Download Delivers GhostDesk The counterfeit installer uses the CCleaner name and icon, but its internal name and original filename do not match known releases. It drops Windows Script Host’s CScript component, gathers basic device details, and replaces a Runtime Broker library with a loader for the next stage. It then alters Chrome’s Security Extension manifest so two scripts, content.js and background.js, load from a local folder when the browser starts. This technique echoes the risk described in malicious extension backdoor campaign, where a rogue add-on can establish enduring browser access. The altered extension calls itself GhostDesk, a label also used by legitimate screen-overlay software. That naming choice may make its screen capture role appear less unusual, but the reported functions point to surveillance rather than a normal browser tool. Malicious Chrome extension (Source – Malwarebytes) GhostDesk records entries typed into form fields and looks for submitted data tied to credentials, authentication tokens, and financial information. It can also replace pasted cryptocurrency addresses, a tactic that could redirect a payment without changing what a victim intended to do. Browser Spyware Raises Stakes The background component can collect browser cookies, capture the active tab, maintain a local relay, and inject attacker-provided JavaScript into an open page. Such broad permissions show why reviewing browser extension permissions should be part of routine account protection, especially on devices used for sensitive work. The malware connects through a local WebSocket endpoint before reaching attacker infrastructure, allowing data and instructions to move between Chrome and the operator. Comparable campaigns have used browser add-ons to quietly gather data at scale, including the long-running ShadyPanda extension campaign, which relied on trusted-looking extensions. Researchers also traced the same loading method to fake 7-Zip and Adobe Acrobat samples, with all observed samples communicating with the same command-and-control domain. One fake Adobe Acrobat variant used wscript.exe rather than cscript.exe, suggesting the operators can adjust the loader while keeping the broader delivery chain intact. Anyone who downloaded the suspected installer should disconnect the machine from sensitive accounts, run a reputable security scan as soon as possible, and remove unfamiliar Chrome extensions. They should also change passwords from a known-clean device, invalidate all account sessions where possible, and watch for unusual sign-ins or unauthorized transactions. Because stolen cookies can bypass a password alone, prompt session revocation matters alongside credential resets. Users should check the address bar carefully before downloading software and avoid treating sponsored results, social posts, text messages, or emailed links as proof that a download is official. When available, obtain software through the publisher’s legitimate site or a trusted store, keep Windows and Chrome updated, and review recent extensions for anything unfamiliar. The recent fake GoogleTranslate extension case is another reminder that a familiar name can hide tools built to steal browser data and remotely control sessions. Indicators of Compromise (IoCs):- Type Indicator Description Domain ccleanerwind[.]top Fake CCleaner download website Domain liderongrade.duckdns[.]org Command-and-control server IP Address 193.169.240[.]81 Command-and-control server SHA-256 c0b4a4af8a3a8c4b113d7f203fcf480cfac79160102490daf287748634b9ce23 FakeCCleaner.exe SHA-256 8d921bdd1f5bc8c03209a5dfacfd9ed313497ac2e3f1b4a2000f4c474a464904 Reflexive loader replacing runtimebroker.dll SHA-256 3d7411e2e445a2210dbbf061f3e8e3dd3476a4fc5d4a2135dcceb0bc705776bf content.js GhostDesk extension SHA-256 cfd9c0bcc89ebc68aae889b9b49bc8290c3764bce5f2c9ac8b5ba0ba58e9bf61 background.js GhostDesk extension SHA-256 590b04e35fc0b3dcd9dabe82f2e96d4d1e0fccc598911cf80f8255232ee75fcb Fake 7-Zip sample SHA-256 ecde892dbc28af620ba8e311fa9dd4c66521c7fe95e6aadacc7cd9a5bb57d32d Fake Adobe Acrobat sample SHA-256 cfa3900cefb447d89a7498224f2ecafa65b190336934811e6c1d4196d9b92452 Fake Adobe Acrobat sample SHA-256 0bf8f52b28291edc505a64962e6ce04387a9784fc5b18aeff53629adb1f72f56 Fake Adobe Acrobat sample using wscript.exe Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM. Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world Tags cyber security cyber security news Copy URL Linkedin Twitter ReddIt Telegram Tushar Subhra Dutta Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics. Cyber Security Guide Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways  Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026) An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response  Latest Cyber News Cyber Security Nightmare-Eclipse Drops ShieldBreak Windows Defender 0-day Vulnerability Cyber Security News CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure Cyber Security News Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals Cyber Security News Google-themed Credential Phishing Attempt Delivered Through a Fake ‘New Audio MSG’ Email Cyber Security News Top 10 Best Business VPN Solutions in 2026 Expert Talks Expert Talks From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking  Expert Talks Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage  Expert Talks Your Incident Response Plan Has a Dependency You Never Approved Expert Talks Security in the AI Era Starts with First Principles  Cyber Security News Planning Your AI Security – How will You Manage All Your Resources?
    💬 Team Notes
    Article Info
    Source
    Cybersecurity News
    Category
    ◇ Industry News & Leadership
    Published
    Aug 12, 2026
    Archived
    Aug 12, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗