logo

Evidence Aurora Operation Still Active Part 2: More Ties Uncovered Between CCleaner Hack & Chinese Hackers

ID: e50ce5d5-30b8-4666-879a-7c5c24918862

STIX ID: report--e50ce5d5-30b8-4666-879a-7c5c24918862

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2017-10-08

Last Modified Date: 2017-10-08

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Intezer's analysis of the CCleaner supply‑chain attack uncovers shared, unique code between the stage‑2 payloads and known Axiom (APT17) samples, provides in‑depth reverse engineering of memory allocation, decompression, registry persistence, service loading of trojanized binaries, and C2 resolution using steganographic tokens on public sites; the report lists multiple IOCs (file hashes and registry keys) and concludes the campaign is likely state‑sponsored.