Skip to content

Gcleaner

GCleaner is a Windows pay-per-install malware loader used to download and execute additional payloads on compromised systems.

Profile source: Mallory opens in a new tab

Gcleaner

Family profile

GCleaner is a Windows pay-per-install malware loader used to download and execute additional payloads on compromised systems. It has also been referred to as Garbage Cleaner and has been observed masquerading as a fake system-cleaning utility, including branding that imitates legitimate cleaning software. The malware is part of the commodity cybercrime loader ecosystem and has been seen both as a standalone PPI loader and as a payload distributed by other malware delivery services such as PrivateLoader, NullMixer, and Amadey-linked campaigns.

GCleaner communicates with command-and-control infrastructure over HTTP, reports installation-related status information, and retrieves additional executables for local execution. Observed samples beacon to remote servers, transmit installation markers associated with BroomCleaner branding, download follow-on binaries, write them to temporary storage, and launch them via standard Windows execution APIs. In at least one analyzed case, the downloaded follow-on payloads were assessed as StealC samples, demonstrating GCleaner’s role as a malware delivery mechanism rather than an end-stage payload.

Distribution has been tied to malicious software-crack and fake-download ecosystems. It has been observed in campaigns using SEO poisoning and lure sites advertising cracked software, where victims are directed to password-protected archives containing installers that deploy multiple malware families. GCleaner has also been associated with fake cleaning-tool lures. Through these ecosystems it has been used alongside or in proximity to families such as Raccoon Stealer, RedLine, SmokeLoader, Vidar, and other commodity malware.

The malware targets Windows systems and is relevant across broad opportunistic victim populations rather than a single vertical. Its operational role is primarily initial payload delivery and staging for financially motivated cybercrime activity.

Capabilities

  • Exfiltration
  • Initial Access
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 24, 2026
Last activity
Aug 29, 2026
Feed role
C2 / Distribution
Host form
12 IP / 15 hostnames

Leading locations

  • US5
  • NL4
  • FR3
  • BR2
  • HK2
  • PL2
  • DE1
  • LU1
  • SG1

Leading providers

  • Hostinger International Limited3
  • Contabo GmbH2
  • OVH SAS2
  • ALINDA LLC1
  • ChangLian Network Technology Co., Limited1
  • Cloudflare, Inc.1

Infrastructure traits

  • Hosting 19
  • Anycast 1

Samples

Recent associated samples

MITRE ATT&CK

Gcleaner in ATT&CK

5 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.