Evidence Aurora Operation Still Active: Supply Chain Attack Through CCleaner
ID: 75d966b8-8e1b-4f58-8d20-957f86f0d001
STIX ID: report--75d966b8-8e1b-4f58-8d20-957f86f0d001
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2017-10-08
Last Modified Date: 2017-10-08
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
A supply-chain backdoor was found in Avast's CCleaner (v5.33.6162) that appears to have been planted in the build process; analysis shows unique base64 implementation and other code overlaps tying the backdoor to APT17/Operation Aurora. The report provides disassembly, loader/PE-in-memory techniques, execution flow, the malicious sample SHA256, a C2 IP (216.126.225.148), and discusses potential wide impact and continued activity by the threat actor.
