APT17__2017__Aurora_Operation_CCleaner_II.pdf
ID: 3025f7d0-0f1f-4e8f-9839-f47ffdbf1530
STIX ID: report--3025f7d0-0f1f-4e8f-9839-f47ffdbf1530
Threat Score
92/100
Uploaded: 2026-08-07
Published Date: 2017-10-24
Last Modified Date: 2017-10-24
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Intezer's technical analysis of the CCleaner supply‑chain attack (stage 2) documents a trojanized legitimate binary and registry‑stored payloads that are decrypted and executed to establish persistence (service named Spooler or SessionEnv), perform memory‑loaded execution, and connect to C2. The report shows code reuse linking the payloads to the Axiom group (APT17), details techniques including LocalAlloc-based staging, zlib decompression, registry-saved shellcode, steganographic retrieval of C2 (ptoken field XOR decrypted to an IP), and provides hashes and registry keys as IOCs.
