Fake CCleaner site turns Chrome into a spying and password-theft tool
Criminals built a convincing copycat download page for one of the world's most-downloaded PC tools, then used it to silently hijack Google Chrome and steal passwords, bank details, and screenshots.

Key points
- Criminals built a fake CCleaner download site at the address "ccleanerwind[.]top" and used it to distribute malware disguised as a legitimate installer.
- The malware plants a hidden extension inside Google Chrome called GhostDesk, which records keystrokes, steals passwords and cookies, captures screenshots, and swaps cryptocurrency wallet addresses.
- Researchers at Malwarebytes identified at least two other fake software sites, impersonating 7-Zip and Adobe Acrobat, using the same criminal infrastructure.
- GhostDesk can also intercept anything copied to the clipboard, meaning a victim who copies a crypto wallet address may unknowingly paste the criminal's address instead.
What happened?
Someone created a near-identical copy of the CCleaner download page. CCleaner is a Windows utility, downloaded more than two billion times globally, that cleans up junk files and speeds up computers. Most people who searched for it and landed on the fake site would have had no obvious reason to doubt it.
Both download buttons on the fake site, the standard version and a "Cleaner Pro" option, delivered the same malicious file. Once a visitor clicked download and ran the installer, a quiet, multi-step attack began.
The file first dropped a legitimate Windows scripting tool called CScript, which is a built-in program Windows uses to run automated tasks, then used that tool to run a chain of hidden scripts. Those scripts quietly gathered basic information about the computer: its unique ID, its hostname, and its language settings. That kind of reconnaissance is standard practice before a criminal decides whether the machine is worth targeting further.
How does the attack actually steal information?
The scripts then modified Google Chrome. Specifically, they altered a file called Chrome's Security Extension manifest, which is the internal document Chrome reads to decide which extensions are allowed to run. The modification let the attackers inject two rogue script files into the browser. Chrome then treated them as a trusted extension, called GhostDesk, from that point on.
GhostDesk has two parts working together.
One part records every key a victim types and scans any form they fill in, hunting for passwords, authentication tokens (the digital passes that keep you logged in without re-entering a password), and financial details. It also watches the clipboard, the temporary storage where text lives after you press copy, and silently replaces any cryptocurrency wallet address the victim copies with the criminals' own address.
The second part steals browser cookies (small files websites use to recognise a returning user), takes screenshots, and maintains a live channel back to the criminals' server. That channel restarts automatically each time Chrome opens, giving the criminals persistent access even after a reboot.
Malwarebytes, the security firm that discovered the campaign and first reported details publicly, tracks the malware under the name GhostDesk.
Should anyone other than CCleaner users be worried?
Yes. Malwarebytes found copycat sites for 7-Zip, a popular free file-compression tool, and Adobe Acrobat, the widely used PDF reader, running the same attack chain and reporting back to the same criminal server.
| Fake software | Delivery method | Same server? |
|---|---|---|
| CCleaner | cscript.exe chain | Yes |
| 7-Zip | cscript.exe chain | Yes |
| Adobe Acrobat | wscript.exe chain (variant) | Yes |
The server address all three used is "liderongrade.duckdns[.]org."
What should you do right now?
Before downloading any software, check the web address carefully. The official CCleaner site is piriform.com; any other domain offering CCleaner is not legitimate. The same principle applies to 7-Zip and Adobe: go to the publisher's own site directly, not through a search result.
Be especially cautious with sponsored search results, the paid links that appear at the top of a Google or Bing search, because criminals frequently buy those ad slots to push fake download pages to the top.
If you downloaded CCleaner, 7-Zip, or Adobe Acrobat from an unfamiliar link recently, run a full scan with an up-to-date anti-malware tool. Malwarebytes says its product detects the fake installer as "Trojan.Dropper" and blocks the criminal server. Change passwords for any account you accessed through Chrome on that machine, and check for any unfamiliar logins in your account activity.



