The CCleaner 5.33.6162 Supply Chain Attack
Updated 5 Oct 2026 · Incident date 15 Aug 2017 · vendor binary
CCleaner 5.32 -> 5.33.6162 (and CCleaner Cloud 1.07.3191)CCleaner.exeCCleaner 5.33.6162 and CCleaner Cloud 1.07.3191 contained a backdoor. Piriform released version 5.33 on 15 August 2017, and the binary carried a valid digital signature. Version 5.34 was the first clean version after it.
Avast, which owned Piriform, says 2.27 million users were affected.
Major incident. Avast reported that the compromised CCleaner release affected 2.27 million computers. This entry covers the same incident as the other CCleaner record. Impact source
What happened
Attackers added code to the CCleaner binary before it was signed. Cisco Talos reports that the file carried a valid certificate issued to Piriform Ltd. Talos identified the threat on 13 September 2017 and notified Avast.
According to Avast, the compromise probably began on 3 July 2017 and the bad release shipped on 15 August. Morphisec notified Avast on 12 September, and the command server was taken down on 15 September. Avast says the second-stage payload never activated, so the only malicious code on customer machines was in the CCleaner binary.
Talos describes the code. It changed the startup callback so that it decrypted a two-stage payload before CCleaner started as normal. The malware:
- waited 601 seconds before it ran
- needed administrator rights
- stored its settings under the registry key
HKLM\SOFTWARE\Piriform\Agomowith valuesMUID,TCIDandNID - sent host information over HTTPS to
216.126.225.148, with the host headerspeccy.piriform.com - used a domain generation algorithm as a fallback if the main server was down
Affected versions
CCleaner 5.33.6162 and CCleaner Cloud 1.07.3191 are the affected builds, and only the 32-bit Windows versions. Avast says the cloud and 32-bit versions were the two affected products.
- 5.32: the clean baseline before the attack
- 5.33.6162: backdoored, released 15 August 2017
- 5.33.6163: fixed build with the backdoor removed, according to Avast
- 5.34: released 12 September 2017 and clean
The free version has no auto-update. Users of the free version had to update by hand.
Indicators of compromise
- SHA-256:
6f7840c77f99049d788155c1351e1560b62b8ad18ad0e9adda8218b9f432f0a9 - SHA-256:
1a4a5123d7b2c534cb3e3168f7032cf9ebf38b9a2a97226d0fdb7933cf6030ff - SHA-256:
36b36ee9515e0a60629d2c722b006b33e543dce1c8c2611053e0651a0bfdb2e9 - Command server:
216.126.225.148 - Registry key
HKLM\SOFTWARE\Piriform\Agomowith valuesMUID,TCIDandNID - Generated domains such as
ab6d54340c1a.comandaba9a949bc1d.com. Talos lists 11 examples and says the algorithm makes new domains each month.
How to check
Check the installed version in the CCleaner About screen. Then check the registry key.
reg query HKLM\SOFTWARE\Piriform\Agomo
If the key exists, the machine ran the backdoored build. Also hash your CCleaner file and compare it with the values above.
Get-FileHash "C:\Program Files\CCleaner\CCleaner.exe" -Algorithm SHA256
What to do now
- Update to CCleaner 5.34 or later.
- Talos advises restoring a machine to a state from before 15 August 2017, or reinstalling it.
- Delete the
Agomoregistry key after you have collected evidence. - Search network logs for the command server address and the generated domains.
- Change credentials that were used on the affected machine.
Vigilance compares the version you trust with a new one and reports the file that gained a new capability. Here a validly signed binary gained host inventory, beaconing and payload decoding. See all attacks.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 85 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED CCleaner.exe It now downloads from the internet and profiles this machine and its user. It did not before.
Frequently asked questions
Which CCleaner version had the backdoor?
CCleaner 5.33.6162 and CCleaner Cloud 1.07.3191, 32-bit Windows builds. Version 5.34 was clean.
How do I check if I ran the backdoored CCleaner?
Check for the registry key HKLM\SOFTWARE\Piriform\Agomo. If it exists, the machine ran the backdoored build.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.