Avast shared new findings from ongoing investigations of CCleaner APT (Advanced Persistent Threat) at RSA. Avast also found ShadowPad samples active in South Korea and Russia, logging a financial transaction. The attackers were in the Piriform network five months before they snuck the malicious payload into the Cleaner build. Avast acquired Piriform on July 18, 2017 and the first CCleaners build appeared on August 2, 2017. The attackers applied several techniques to infiltrate other computers in the internal network, including using passwords gathered by the keylogger.”]
Source: https://blog.avast.com/update-ccleaner-attackers-entered-via-teamviewer

