Skip to content

Gcleaner

GCleaner is a malware family identified in the provided reporting as a pay-per-install (PPI) loader and as a fake cleaning tool used across multiple campaigns.

Profile source: Mallory opens in a new tab

Gcleaner

Family profile

GCleaner is a malware family identified in the provided reporting as a pay-per-install (PPI) loader and as a fake cleaning tool used across multiple campaigns. It was observed among the 24 malware families distributed in a March 2026 Amadey botnet campaign tagged "fbf543," which Breakglass Intelligence assessed as a financially motivated PPI operation likely linked to the CIS cybercrime ecosystem. In that campaign, GCleaner was delivered alongside numerous other payloads including Vidar, LummaStealer, QuasarRAT, XWorm, SmokeLoader, AsyncRAT, DarkVisionRAT, HijackLoader, CoinMiner, and remote access tooling such as ConnectWise ScreenConnect. The campaign used Amadey infrastructure including sys32[.]cc as a Cloudflare-proxied C2 and labinstalls[.]info at 158.94.211.222 for backend payload hosting, with additional delivery infrastructure on qpgroup[.]top. Separately, Gcleaner is also explicitly described as a fake cleaning tool used in AuraStealer distribution chains, where AuraStealer operators employed loaders, DLL sideloading, malicious .NET DLLs, Donut shellcode loaders, process injection into legitimate Windows binaries, and social-engineering-driven delivery such as ClickFix. One mention context also lists suspected GCleaner C2 infrastructure under /advertisting/plus.php on 45.12.253.56, with related IPs 45.12.253.72 and 45.12.253.98. Based on the provided content, the high-confidence characterization is that GCleaner is a fake cleaner-themed loader used as part of criminal malware delivery ecosystems rather than a standalone stealer or RAT.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 1, 2026
Last activity
Aug 7, 2026
Feed role
C2 / Distribution
Host form
9 IP / 2 hostnames

Leading locations

  • NL3
  • AT1
  • DE1
  • EE1
  • GB1
  • MX1
  • US1

Leading providers

  • BlueVPS OU1
  • ChangLian Network Technology Co., Limited1
  • Community Fibre Limited1
  • FOP Dmytro Nedilskyi1
  • Megacable Comunicaciones de Mexico, S.A. de C.V.1
  • Omegatech LTD1

Infrastructure traits

  • Hosting 6
  • Vpn 1

Samples

Recent associated samples

MITRE ATT&CK

Gcleaner in ATT&CK

2 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.