Avast outlines how hackers hid a backdoor in its PC cleanup tool CCleaner, which tainted ~2.27M downloads in 2017, as part of a targeted attack on tech firms
IN SEPTEMBER, SECURITY researchers at Cisco Talos and Morphisec made a worst nightmare-type disclosure: the ubiquitous computer … Tweets: @beauwoods Tweets: Beau Woods / @beauwoods : In 2017 acquisition, a security company a) did no security diligence; b) had not considered security diligence; c) thought it was a novel concept in M&A. Does that seem odd? http://www.wired.com/... http://twitter.com/...
Context & Ripple Effects
When CCleaner's backdoor surfaced in September 2017, Cisco Talos and Morphisec traced roughly 2.27M tainted downloads to a staged second-stage payload aimed at corporate networks. A follow-up Talos report showed the attackers had reached machines inside at least 20 tech firms, including Akamai, Cisco, Google, Intel, and Microsoft.
This piece is Avast's own post-mortem, published months after the disclosure — and it lands amid two developments that keep the story alive: researchers have since tied CCleaner to a cluster of six linked supply chain attacks, including a backdoor in Asus' software update tool, and hackers breached Avast's internal network in 2019 in what looked like another attempt at CCleaner. Security researcher Beau Woods uses the episode to flag a sharper question: how did a security company acquire the tool without security diligence?
First-order effects
- Avast's technical account puts its own acquisition practices under scrutiny — Woods' critique centers on a security firm that reportedly did no security diligence when buying the tool it now has to explain.
- The at least 20 targeted tech firms named in the Talos reporting — Akamai, Cisco, Google, Intel, Microsoft among them — get confirmation that the intrusion vector ran through a utility their employees trusted.
Second-order effects
- Vendors of ubiquitous system utilities face forced scrutiny of their build and update pipelines, a pressure made concrete by the Asus update-tool backdoor in the same attributed campaign.
- Enterprise buyers gain reason to treat mass-distributed cleanup and update tools as privileged attack surface rather than commodity freeware, repricing trust in exactly the category CCleaner dominates.
Third-order effects
- If the six-attack attribution holds, the structural lesson is that compromising one trusted distributor scales better than attacking end targets one by one — making software supply chains the recurring target class, and pushing security diligence into M&A as standard practice.
The trend: Attackers are shifting from breaching individual targets to poisoning widely distributed software updates, turning every trusted vendor into a potential delivery channel.