Last seven days
- First activity
- Aug 1, 2026
- Last activity
- Aug 7, 2026
- Feed role
- C2 / Distribution
- Host form
- 9 IP / 2 hostnames
GCleaner is a malware family identified in the provided reporting as a pay-per-install (PPI) loader and as a fake cleaning tool used across multiple campaigns.
Profile source: Mallory opens in a new tabGcleaner
GCleaner is a malware family identified in the provided reporting as a pay-per-install (PPI) loader and as a fake cleaning tool used across multiple campaigns. It was observed among the 24 malware families distributed in a March 2026 Amadey botnet campaign tagged "fbf543," which Breakglass Intelligence assessed as a financially motivated PPI operation likely linked to the CIS cybercrime ecosystem. In that campaign, GCleaner was delivered alongside numerous other payloads including Vidar, LummaStealer, QuasarRAT, XWorm, SmokeLoader, AsyncRAT, DarkVisionRAT, HijackLoader, CoinMiner, and remote access tooling such as ConnectWise ScreenConnect. The campaign used Amadey infrastructure including sys32[.]cc as a Cloudflare-proxied C2 and labinstalls[.]info at 158.94.211.222 for backend payload hosting, with additional delivery infrastructure on qpgroup[.]top. Separately, Gcleaner is also explicitly described as a fake cleaning tool used in AuraStealer distribution chains, where AuraStealer operators employed loaders, DLL sideloading, malicious .NET DLLs, Donut shellcode loaders, process injection into legitimate Windows binaries, and social-engineering-driven delivery such as ClickFix. One mention context also lists suspected GCleaner C2 infrastructure under /advertisting/plus.php on 45.12.253.56, with related IPs 45.12.253.72 and 45.12.253.98. Based on the provided content, the high-confidence characterization is that GCleaner is a fake cleaner-themed loader used as part of criminal malware delivery ecosystems rather than a standalone stealer or RAT.
C2 tracking
Derp observations, rolling seven-day window
Samples
67cd5f1b19d33786a9f73b630357cce0d90d6771590ccb965fb331ffc6d4fb94 73fc2d3057331b8382c4e0e833f495c2843bfb36a48d7e765ddbc1be241e5a67 d2555e5f817810e4839bb5c163514cf4807b5f9878708a519d68e52f5d48e7ab dbd1aae6e2a47af68e987dbfcc91c564d17c532e892938983eac8f891dec81b9 f1fe7bb2031c73328ccb32730d319b8ba0dabca108addd1135468a75fed36b8f 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 b7a06c7dd0943016ee68b5c14ec8a20578df56f9d9fa5f6ea73df6daa5211c07 f270a80b90acb4302bb29b2f4c7436f6d7eedc4738ca63351f59f22bd59ce28d f5ebd8f8e5217df1c726beb523c00d49992d6d205589509cbe2c581b6aab29b6 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.