The CCleaner 5.33.6162 Supply Chain Attack

Updated 5 Oct 2026 · Incident date 15 Aug 2017 · vendor binary

PackageCCleaner 5.32 -> 5.33.6162 (and CCleaner Cloud 1.07.3191)
FileCCleaner.exe

CCleaner 5.33.6162 and CCleaner Cloud 1.07.3191 contained a backdoor. Piriform released version 5.33 on 15 August 2017, and the binary carried a valid digital signature. Version 5.34 was the first clean version after it.

Avast, which owned Piriform, says 2.27 million users were affected.

Major incident. Avast reported that the compromised CCleaner release affected 2.27 million computers. This entry covers the same incident as the other CCleaner record. Impact source

What happened

Attackers added code to the CCleaner binary before it was signed. Cisco Talos reports that the file carried a valid certificate issued to Piriform Ltd. Talos identified the threat on 13 September 2017 and notified Avast.

According to Avast, the compromise probably began on 3 July 2017 and the bad release shipped on 15 August. Morphisec notified Avast on 12 September, and the command server was taken down on 15 September. Avast says the second-stage payload never activated, so the only malicious code on customer machines was in the CCleaner binary.

Talos describes the code. It changed the startup callback so that it decrypted a two-stage payload before CCleaner started as normal. The malware:

Affected versions

CCleaner 5.33.6162 and CCleaner Cloud 1.07.3191 are the affected builds, and only the 32-bit Windows versions. Avast says the cloud and 32-bit versions were the two affected products.

The free version has no auto-update. Users of the free version had to update by hand.

Indicators of compromise

How to check

Check the installed version in the CCleaner About screen. Then check the registry key.

reg query HKLM\SOFTWARE\Piriform\Agomo

If the key exists, the machine ran the backdoored build. Also hash your CCleaner file and compare it with the values above.

Get-FileHash "C:\Program Files\CCleaner\CCleaner.exe" -Algorithm SHA256

What to do now

  1. Update to CCleaner 5.34 or later.
  2. Talos advises restoring a machine to a state from before 15 August 2017, or reinstalling it.
  3. Delete the Agomo registry key after you have collected evidence.
  4. Search network logs for the command server address and the generated domains.
  5. Change credentials that were used on the affected machine.

Vigilance compares the version you trust with a new one and reports the file that gained a new capability. Here a validly signed binary gained host inventory, beaconing and payload decoding. See all attacks.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old CCleaner-5.32 --new CCleaner-5.33.6162
files scanned: 85

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    CCleaner.exe
           It now downloads from the internet and profiles this machine and its user. It did not before.

Frequently asked questions

Which CCleaner version had the backdoor?

CCleaner 5.33.6162 and CCleaner Cloud 1.07.3191, 32-bit Windows builds. Version 5.34 was clean.

How do I check if I ran the backdoored CCleaner?

Check for the registry key HKLM\SOFTWARE\Piriform\Agomo. If it exists, the machine ran the backdoored build.

Sources

  1. blog.talosintelligence.com/avast-distributes-malware/
  2. blog.avast.com/update-to-the-ccleaner-5.33.6162-security-incident

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free