2.27 customers installed the altered version of the CCleaner and the malware introduced in Piriform servers sometime between March 11 and July 4, 2017. Avast shared the report at the Security Analyst Summit in Mexico, researchers said the malware was installed on the built servers of Piriform. The third stage of the payload is the ShadowPad that cybercriminals install in the victims network to gain remote access. The second-stage binary installed only in 40 computer out of millions which makes it as the attack on sensitive networks.”]
Source: https://gbhackers.com/ccleaner-hack-report-keystore/

