13:58 20.09.2017

CCleaner vulnerability removed – Ukraine's cyber police

2 min read
CCleaner vulnerability removed – Ukraine's cyber police

The developer of the CCleaner (5.34) and CCleaner Cloud (v.1.07.3214) software has released security updates for its products that are free from the Floxif malware, which was found in the 32-bit version of CCleaner 5.33.6162 and CCleaner Cloud 1.07.3191, the Ukrainian National Police's cyber unit has said.

"Malware Floxif gathered information from compromised systems and had the ability to upload additional malware code into the system. Users of CCleaner should immediately upload the abovementioned updates from the company," Ukraine's cyber police said on its Facebook page.

Ukraine's cyber police on September 19 warned about the malware contained in an earlier update of the CCleaner program, which was created for helping users to conduct planned technical servicing of their systems. Information about the CCleaner (5.33) virus came from a unit of the Cisco Talos company.

The virus-infected version of the program was released from August 15 to September 12, 2017. The version was verified for use with a valid digital certificate, which was released by Symantec Piriform Ltd., leading users to believe that they were using reliable software.

The attack was prevented, at the same time some 100 IP addresses were connecting to a server controlled by hackers.

In order to prevent the virus from spreading and removing all technical problems, the cyber police sent official letters to Internet providers, noting the IP addresses of infected computers in order that users could independently remove the corrupted software from their personal computers.

Cyber police specialists also made the recommendation to Ukrainian users to temporarily not use CCleaner and look for analogous products.

AD
AD
AD
AD