CCBkdr

S0222

Malware.View on attack.mitre.org

About this malware

CCBkdr is malware that was injected into a signed version of CCleaner and distributed from CCleaner's distribution website.

Techniques used2

Procedure examples2

TechniqueProcedure example
T1195.002
Compromise Software Supply Chain

CCBkdr was added to a legitimate, signed version 5.33 of the CCleaner software and distributed on CCleaner's distribution site.

T1568.002
Domain Generation Algorithms

CCBkdr can use a DGA for Fallback Channels if communications with the primary command and control server are lost.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. Intezer Aurora Sept 2017 Open source
    Rosenberg, J. (2017, September 20). Evidence Aurora Operation Still Active: Supply Chain Attack Through CCleaner. Retrieved February 13, 2018.
  2. Talos CCleanup 2017 Open source
    Brumaghin, E. et al. (2017, September 18). CCleanup: A Vast Number of Machines at Risk. Retrieved March 9, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.