Hackers breached the internal network of Avast likely aiming for another supply chain attack on CCleaner; Avast says it didn't find malicious changes to the app
again Robert Lemos / Dark Reading : Avast Foils Another CCleaner Attack Alex Scroxton / ComputerWeekly.com : Attacker hit VPN firm Avast through its VPN Seth Rosenblatt / The Parallax : SafeBreach discloses vulnerabilities in Avast, AVG, Avira Tweets: @briankrebs : Breaches acknowledged this week by Avast (a la CCleaner) and NordVPN tied to phantom user accounts, no 2FA https://krebsonsecurity.com/ ... pic.twitter.com/eOWuT2cofF Vincent Yiu / @vysecurity : Mate I think you're dizzy. How is getting “Domain Admin”, attempting to be stealth? Tracked them for a few months? Sounds a bit crappy because who leaves the attacker with DA privileges for 2 months to track them 🧐 https://twitter.com/...
Context & Ripple Effects
This is a repeat, not a debut: in 2017 attackers hid a backdoor in CCleaner that tainted roughly 2.27M downloads, and Avast's own postmortem of the CCleaner backdoor described it as a targeted campaign against tech firms. Two years later, someone is back inside Avast's internal network with what looks like the same objective.
The breach lands while Avast's defenses are already under scrutiny — SafeBreach has just disclosed vulnerabilities across Avast, AVG, and Avira, and Brian Krebs' reporting ties the intrusion to phantom user accounts without two-factor authentication. Avast says it found no malicious changes to CCleaner this time, but the 2017 incident proved the update pipeline is exactly what attackers want.
First-order effects
- Avast must re-verify its CCleaner build-and-signing pipeline end to end and convince 2.27M-plus users — the same population burned by the 2017 backdoor — that no second tampering occurred.
- The disclosed SafeBreach vulnerabilities and the reported missing two-factor authentication now compound into a concrete security-posture problem for Avast and its AVG customer base.
Second-order effects
- Enterprise buyers of endpoint software face an uncomfortable pattern: BitDefender admitted a breach back in 2015, and now Avast — meaning the vendors selling trust are themselves recurring targets, pressuring rivals to publish their own build-integrity controls.
- Security vendors' update channels become a priced-in risk in procurement, the same dynamic now playing out with remote-access firms after TeamViewer's corporate-environment breach.
Third-order effects
- The recurring sequence — CCleaner in 2017, 3CX's desktop client in 2023, TeamViewer in 2024 — points toward corporate IT networks of security and remote-access vendors becoming the preferred supply-chain entry point, shifting the battleground from end-user machines to vendor build infrastructure.
- If intrusions keep targeting the vendors themselves, expect regulators and enterprise customers to demand verifiable build provenance and hardened identity controls (2FA, account hygiene) as a condition of trust rather than a best practice.
The trend: Supply-chain attackers are increasingly skipping end targets and compromising the security and remote-access vendors themselves, making vendor build pipelines the industry's systemic weak point.