The CCleaner 5.33.6162 Supply Chain Attack
Updated 5 Oct 2026 · Incident date 15 Aug 2017 · vendor binary
CCleaner 5.32 -> 5.33.6162 (and CCleaner Cloud 1.07.3191)CCleaner.exeCCleaner 5.33.6162 and CCleaner Cloud 1.07.3191, both 32-bit Windows builds, carried a backdoor that was released on 15 August 2017. Avast reports that 2.27 million users ran the bad version. The fixed version of CCleaner is 5.34.
The bad program was signed with Piriform's own certificate, so it looked genuine.
Major incident. Avast reported that the compromised CCleaner release affected 2.27 million computers. This is not a count of second-stage infections. Impact source
What happened
Attackers placed malicious code inside the CCleaner program before it was built and signed. Morphisec reports that the binary remained signed by the original Piriform build machine. Avast bought Piriform, the maker of CCleaner, on 18 July 2017. Avast states that the compromise most likely began around 3 July 2017, going by a certificate timestamp, and that the bad build was released on 15 August 2017. It ran undetected for about four weeks.
Morphisec describes the mechanism. The code changed a function in the Visual Studio runtime so that it ran before the real CCleaner code. It loaded a DLL straight into memory. The payload was a controller that collected system information and contacted command servers. It used a domain generation algorithm with the month as a seed as a fallback. It was able to download and run more code. VulnCheck lists CVE-2017-20201 for the flaw.
Morphisec identified and blocked malicious installs from 20 and 21 August 2017 and told Avast on 12 September. Cisco reported its own findings on 14 September. Avast took the command server down on 15 September, and the public disclosure came on 18 September.
Avast states that the only malicious code on customer machines was in ccleaner.exe and that the second-stage payload never activated on affected machines.
Vigilance compares the version you trust with the new one. This build ran new code before the program started, and Vigilance reports the file that gained that capability. See the scan block below.
Affected versions
- CCleaner 5.33.6162, 32-bit Windows build.
- CCleaner Cloud 1.07.3191, 32-bit Windows build. VulnCheck dates this to 24 August 2017.
Avast states that 5.34 and the versions before 5.33.6162 are not affected. Avast also released 5.33.6163. The fixed Cloud version is 1.07.3214, released on 15 September 2017 (VulnCheck).
Indicators of compromise
- File:
ccleaner.exewith the file version 5.33.6162. - CCleaner Cloud file version 1.07.3191.
- A signed, genuine-looking binary whose startup code runs a custom loader before the normal entry point.
- Outbound HTTPS to command servers, or to domains from a generation algorithm seeded by the month.
The sources fetched here list no domains or hashes, so this page lists none. Check the Avast and Morphisec reports for details.
How to check
Read the version of the installed program. In PowerShell:
(Get-Item "$env:ProgramFiles\CCleaner\CCleaner.exe").VersionInfo.FileVersion
Version 5.33.6162 is the bad one. For CCleaner Cloud, check the installed version in Apps. On a 64-bit system the path can be different, so search for CCleaner*.exe if the command returns nothing.
What to do now
- Update CCleaner to 5.34 or later. Update CCleaner Cloud to 1.07.3214 or later.
- Avast states that restoring a system to a state before 15 August 2017 is not needed after the update.
- Look for outbound traffic to unknown servers from the program in your logs.
- Keep a list of the installed versions of utility software. Remove tools that you do not use.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 87 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED CCleaner.exe It now downloads from the internet and runs other programs. It did not before.
Frequently asked questions
Which CCleaner version contained the backdoor?
CCleaner 5.33.6162 and CCleaner Cloud 1.07.3191, both 32-bit Windows builds, contained the backdoor.
How many users ran the compromised CCleaner?
Avast reports 2.27 million users ran the compromised version.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.