logo

APT17__2017__Aurora_Operation_CCleaner_II.pdf

ID: 3025f7d0-0f1f-4e8f-9839-f47ffdbf1530

STIX ID: report--3025f7d0-0f1f-4e8f-9839-f47ffdbf1530

Threat Score

92/100

Uploaded: 2026-08-07

Published Date: 2017-10-24

Last Modified Date: 2017-10-24

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Intezer's technical analysis of the CCleaner supply‑chain attack (stage 2) documents a trojanized legitimate binary and registry‑stored payloads that are decrypted and executed to establish persistence (service named Spooler or SessionEnv), perform memory‑loaded execution, and connect to C2. The report shows code reuse linking the payloads to the Axiom group (APT17), details techniques including LocalAlloc-based staging, zlib decompression, registry-saved shellcode, steganographic retrieval of C2 (ptoken field XOR decrypted to an IP), and provides hashes and registry keys as IOCs.