News

Utilize Proactive Monitoring & CCleaner Hack

Posted: Monday, September 25, 2017

Author: Mark Risidore

You may have seen in the news recently Piriform’s announcement that their well-known and widely used software had been compromised by malicious hackers. This was covered in a BBC article entitled: Alert over booby-trapped security software.

CCleaner is a piece of software that is used globally to clean up unnecessary files on PCs and servers in an attempt to make devices run faster and more reliably. However, hackers have managed to insert malicious code into this application meaning they could have covertly taken over an estimated 2.27million computers worldwide.

NOTE: This does not apply to all versions of CCleaner. Affected builds are the 32-bit CCleaner versions 5.33.6162 or CCleaner Cloud 1.07.3191 released in 15th August 2017.

Proactive response from Utilize

Here at Utilize, when our security experts became aware of the attack, they turned to our AIM system (Advanced Infrastructure Monitoring) to see how we could help mitigate the risk to our customers. Using AIM, our monitoring team managed to create a custom detection rule for these affected build numbers, and applied this to our clients’ servers. This meant we were able to remove the affected software from all customer devices at a click of a button.

Although the payload was never activated, due to the hacker’s command servers being taken offline by the authorities, this demonstrates one of the many benefits that our advanced monitoring brings to our customers.

For more information on AIM or any other aspect of Utilize IT support, please contact your account manager or email info@utilize.co.uk.

Our web site uses cookies, including Google Analytics cookies, to better understand how you use our site. Read our Cookie Policy for more information including Google Options. By using our web site you accept our use of cookies as detailed in our Cookie Policy.