Fake CCleaner Site Drops GhostDesk Chrome Spyware

Malwarebytes · High sophistication
Last updated August 11, 2026

Attackers are distributing a fake CCleaner installer from a convincing lookalike website to trick Windows users into installing spyware. The malware modifies Google Chrome and installs a malicious extension (“GhostDesk”) that can steal credentials, capture screenshots, and log keystrokes.

Key findings

  • A lookalike CCleaner download site delivers a malicious “CCleaner.exe” instead of the real installer.
  • The fake installer patches Chrome’s Security Extension and drops JavaScript files that act as a malicious extension labeled “GhostDesk.”
  • The GhostDesk extension supports keylogging, form-data theft, cookie theft, tab screenshots, and remote script execution in the browser.
  • Multiple other fake installers (e.g., 7-Zip and Adobe Acrobat) were found using the same infection chain and C2 domain.

Who’s being targeted

  • Commonly targeted roles: All employees, IT support / helpdesk, Desktop engineering / endpoint teams, Security awareness program participants.
  • Affected industries: Any organization where employees download software to Windows endpoints, General consumer and enterprise Windows environments.
  • Attack channels: website.
  • Impersonated: CCleaner (official download page).

Awareness takeaways

  • Train users to verify the exact website address before downloading software (lookalike domains are a common trap).
  • Warn employees that a professional-looking download page (or a “Pro” button) is not proof the site is legitimate.
  • Treat software-download links from ads and shared links (social media, SMS, email) as high risk; prefer trusted stores or the known official site.
  • Explain that ‘utility installers’ can hide spyware behavior; users should avoid downloading tools outside approved channels.

Red flags to watch for

  • Lookalike domain (not the real vendor site): ccleanerwind[.]top
  • Both the “Pro” and normal download buttons deliver the same executable
  • Installer filename/icon match the real app, but internal details don’t match a real release
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You google CCleaner, click a download, and boom, your Chrome quietly turns into a keylogger. This fake site at ccleanerwind.top gives you a bogus 'CCleaner.exe' that patches Chrome and sneaks in a GhostDesk extension to log keys, steal forms and cookies, and screenshot your tabs. The trap: the page looks polished, even has a shiny Pro button, but both buttons drop the same spyware installer, and once it’s in, GhostDesk can see what you type into work apps and websites. Here’s the move: when you need CCleaner, 7-Zip, or Acrobat, don’t trust search ads or random links, type the official site yourself or use our approved software portal.

Categories

Similar attacks

Korea Flags Job-Offer Phish + Watering Holes

Korea Flags Job-Offer Phish + Watering Holes

South Korean agencies warned that a state-backed hacking group is actively targeting citizens and businesses using job-themed phishing emails and “watering hole” attacks on legitimate websites. The phishing lures include fake job applicants sending resume links and impersonated recruiters sending…

July 31, 2026
Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Microsoft says a Russian-linked group is abusing hotel and conference Wi‑Fi “captive portals” to trick travelers into entering corporate credentials or installing malware. Victims see what looks like a normal Wi‑Fi login flow, but attackers manipulate DNS/website traffic to redirect them to fake…

August 4, 2026
Odyssey Piracy Traps: Fake Alerts and EXE “Movies”

Odyssey Piracy Traps: Fake Alerts and EXE “Movies”

Researchers reported that scammers set up cloned piracy sites within hours of Christopher Nolan’s The Odyssey release to trick people looking for pirated copies. The scams used a fake “Browser Issue Detected” pop-up to push users into malicious ad redirects and a Windows .exe file disguised as a…

July 20, 2026
Odyssey Piracy Lures Push Fake Fixes and EXE “Movies”

Odyssey Piracy Lures Push Fake Fixes and EXE “Movies”

Scammers quickly set up fake piracy pages for Christopher Nolan’s “The Odyssey” to trick people into either clicking a fake browser “Fix It Now” warning or downloading a “movie” that is actually a Windows program. The goal is to route victims through malicious advertising redirects or get them to…

July 20, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Fake Free COD Points Scam Steals Logins and 2FA

Fake Free COD Points Scam Steals Logins and 2FA

A real phishing campaign targeted Call of Duty Mobile players by promising free in-game currency. Victims were tricked into entering their email and password, then providing a 2FA code on a follow-up page, enabling attackers to take over accounts.

August 2, 2026