Windows users seeking a familiar cleanup tool are often lured to deceptive counterfeit pages, where they unwittingly download GhostDesk—a malicious Chrome extension designed to monitor browser activity. This campaign turns routine software downloads into avenues for credential theft, keystroke logging, screenshot capturing, cookie collection, and commands delivered to browser tabs. Browser Spyware Raises Stakes The background component collects browser cookies, captures active tabs, maintains a local relay, and injects attacker-provided JavaScript into open pages.

Users who have downloaded suspected installers should disconnect their machines from sensitive accounts, run a reputable security scan as soon as possible, and remove any unfamiliar Chrome extensions.

Users should scrutinize the address bar before downloading software and avoid accepting sponsored results, social posts, text messages, or emails containing links as official downloads. Here are some indicators of compromise (IoCs): - Domain: ccleanerwind[. ]top - Fake CCleaner download website - Domain: liderongrade.duckdns[.

]org - Command-and-control server - IP Address: 193.169.240[. ]81 - Command-and-control server SHA-256 c0b4a4af8a3a8c4b113d7f203fcf480cfac79160102490daf287748634b9ce23 FakeCCleaner.exe SHA-256 8d921bdd1f5bc8c03209a5dfacfd9ed313497ac2e3f1b4a2000f4c474a464904 Reflexive loader replacing runtimebroker.dll SHA-256 3d7411e2e445a2210dbbf061f3e8e3dd3476a4fc5d4a2135dcceb0bc705776bf content.js GhostDesk extension SHA-256 cfd9c0bcc89ebc68aae889b9b49bc8290c3764bce5f2c9ac8b5ba0ba58e9bf61 background.js GhostDesk extension SHA-256 590b04e35fc0b3dcd9dabe82f2e96d4d1e0fccc598911cf80f8255232ee75fcb Fake 7-Zip sample SHA-256 ecde892dbc28af620ba8e311fa9dd4c66521c7fe95e6aadacc7cd9a5bb57d32d Fake Adobe Acrobat sample SHA-256 cfa3900cefb447d89a7498224f2ecafa65b190336934811e6c1d4196d9b92452 Fake Adobe Acrobat sample SHA-256 0bf8f52b28291edc505a64962e6ce04387a9784fc5b18aeff53629adb1f72f56 Fake Adobe Acrobat sample using wscript.exe Prevent future phishing and malware attacks by integrating real-time intelligence from 15,000 SOC teams worldwide.