The CCleaner 5.33.6162 Supply Chain Attack

Updated 5 Oct 2026 · Incident date 15 Aug 2017 · vendor binary

PackageCCleaner 5.32 -> 5.33.6162 (and CCleaner Cloud 1.07.3191)
FileCCleaner.exe

CCleaner 5.33.6162 and CCleaner Cloud 1.07.3191, both 32-bit Windows builds, carried a backdoor that was released on 15 August 2017. Avast reports that 2.27 million users ran the bad version. The fixed version of CCleaner is 5.34.

The bad program was signed with Piriform's own certificate, so it looked genuine.

Major incident. Avast reported that the compromised CCleaner release affected 2.27 million computers. This is not a count of second-stage infections. Impact source

What happened

Attackers placed malicious code inside the CCleaner program before it was built and signed. Morphisec reports that the binary remained signed by the original Piriform build machine. Avast bought Piriform, the maker of CCleaner, on 18 July 2017. Avast states that the compromise most likely began around 3 July 2017, going by a certificate timestamp, and that the bad build was released on 15 August 2017. It ran undetected for about four weeks.

Morphisec describes the mechanism. The code changed a function in the Visual Studio runtime so that it ran before the real CCleaner code. It loaded a DLL straight into memory. The payload was a controller that collected system information and contacted command servers. It used a domain generation algorithm with the month as a seed as a fallback. It was able to download and run more code. VulnCheck lists CVE-2017-20201 for the flaw.

Morphisec identified and blocked malicious installs from 20 and 21 August 2017 and told Avast on 12 September. Cisco reported its own findings on 14 September. Avast took the command server down on 15 September, and the public disclosure came on 18 September.

Avast states that the only malicious code on customer machines was in ccleaner.exe and that the second-stage payload never activated on affected machines.

Vigilance compares the version you trust with the new one. This build ran new code before the program started, and Vigilance reports the file that gained that capability. See the scan block below.

Affected versions

Avast states that 5.34 and the versions before 5.33.6162 are not affected. Avast also released 5.33.6163. The fixed Cloud version is 1.07.3214, released on 15 September 2017 (VulnCheck).

Indicators of compromise

The sources fetched here list no domains or hashes, so this page lists none. Check the Avast and Morphisec reports for details.

How to check

Read the version of the installed program. In PowerShell:

(Get-Item "$env:ProgramFiles\CCleaner\CCleaner.exe").VersionInfo.FileVersion

Version 5.33.6162 is the bad one. For CCleaner Cloud, check the installed version in Apps. On a 64-bit system the path can be different, so search for CCleaner*.exe if the command returns nothing.

What to do now

  1. Update CCleaner to 5.34 or later. Update CCleaner Cloud to 1.07.3214 or later.
  2. Avast states that restoring a system to a state before 15 August 2017 is not needed after the update.
  3. Look for outbound traffic to unknown servers from the program in your logs.
  4. Keep a list of the installed versions of utility software. Remove tools that you do not use.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old CCleaner-5.32 --new CCleaner-5.33.6162
files scanned: 87

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    CCleaner.exe
           It now downloads from the internet and runs other programs. It did not before.

Frequently asked questions

Which CCleaner version contained the backdoor?

CCleaner 5.33.6162 and CCleaner Cloud 1.07.3191, both 32-bit Windows builds, contained the backdoor.

How many users ran the compromised CCleaner?

Avast reports 2.27 million users ran the compromised version.

Sources

  1. blog.avast.com/update-to-the-ccleaner-5.33.6162-security-incident
  2. vulncheck.com/advisories/ccleaner-and-ccleaner-cloud-malicious-backdoor-supply-chain-compromise
  3. morphisec.com/blog/morphisec-discovers-ccleaner-backdoor/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free