Fake CCleaner Site Drops GhostDesk Chrome Spyware

Malwarebytes · High sophistication
Last updated August 11, 2026

Attackers are distributing a fake CCleaner installer from a convincing lookalike website to trick Windows users into installing spyware. The malware modifies Google Chrome and installs a malicious extension (“GhostDesk”) that can steal credentials, capture screenshots, and log keystrokes.

Key findings

  • A lookalike CCleaner download site delivers a malicious “CCleaner.exe” instead of the real installer.
  • The fake installer patches Chrome’s Security Extension and drops JavaScript files that act as a malicious extension labeled “GhostDesk.”
  • The GhostDesk extension supports keylogging, form-data theft, cookie theft, tab screenshots, and remote script execution in the browser.
  • Multiple other fake installers (e.g., 7-Zip and Adobe Acrobat) were found using the same infection chain and C2 domain.

Who’s being targeted

  • Commonly targeted roles: All employees, IT support / helpdesk, Desktop engineering / endpoint teams, Security awareness program participants.
  • Affected industries: Any organization where employees download software to Windows endpoints, General consumer and enterprise Windows environments.
  • Attack channels: website.
  • Impersonated: CCleaner (official download page).

Awareness takeaways

  • Train users to verify the exact website address before downloading software (lookalike domains are a common trap).
  • Warn employees that a professional-looking download page (or a “Pro” button) is not proof the site is legitimate.
  • Treat software-download links from ads and shared links (social media, SMS, email) as high risk; prefer trusted stores or the known official site.
  • Explain that ‘utility installers’ can hide spyware behavior; users should avoid downloading tools outside approved channels.

Red flags to watch for

  • Lookalike domain (not the real vendor site): ccleanerwind[.]top
  • Both the “Pro” and normal download buttons deliver the same executable
  • Installer filename/icon match the real app, but internal details don’t match a real release
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You google CCleaner, click a download, and boom, your Chrome quietly turns into a keylogger. This fake site at ccleanerwind.top gives you a bogus 'CCleaner.exe' that patches Chrome and sneaks in a GhostDesk extension to log keys, steal forms and cookies, and screenshot your tabs. The trap: the page looks polished, even has a shiny Pro button, but both buttons drop the same spyware installer, and once it’s in, GhostDesk can see what you type into work apps and websites. Here’s the move: when you need CCleaner, 7-Zip, or Acrobat, don’t trust search ads or random links, type the official site yourself or use our approved software portal.

Categories

Similar attacks

Fake GTA 6 Demo Sites Push Password Stealer

Fake GTA 6 Demo Sites Push Password Stealer

Attackers are exploiting GTA 6 hype by creating convincing fake Rockstar-branded “demo” websites that appear in Google search results. The sites use “Play Now”/“Official Download” lures to trick people into downloading a small Windows executable that installs Vidar infostealer and steals saved…

August 24, 2026
Fake Verification Pages Push PavinLoader Malware

Fake Verification Pages Push PavinLoader Malware

Malwarebytes reports that a multi-stage Windows malware loader called PavinLoader is being delivered through multiple real-world campaigns, including ClickFix “verification” pages and fake software downloads. Victims are tricked into running installers or scripts that use legitimate Windows tools…

August 24, 2026
Korea Flags Job-Offer Phish + Watering Holes

Korea Flags Job-Offer Phish + Watering Holes

South Korean agencies warned that a state-backed hacking group is actively targeting citizens and businesses using job-themed phishing emails and “watering hole” attacks on legitimate websites. The phishing lures include fake job applicants sending resume links and impersonated recruiters sending…

July 31, 2026
Fake LinkedIn Coding Tests Deliver Mirage Kitten Malware

Fake LinkedIn Coding Tests Deliver Mirage Kitten Malware

Kaspersky reported that Iran-linked APT Mirage Kitten approached software engineers on LinkedIn using fake recruiter personas and sent “coding challenges” that were actually trojanized projects. The lure used legitimate-looking cloud hosting (Amazon S3) and even instructed victims not to use AI…

September 2, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026