Last seven days
- First activity
- Aug 24, 2026
- Last activity
- Aug 29, 2026
- Feed role
- C2 / Distribution
- Host form
- 12 IP / 15 hostnames
GCleaner is a Windows pay-per-install malware loader used to download and execute additional payloads on compromised systems.
Profile source: Mallory opens in a new tabGcleaner
GCleaner is a Windows pay-per-install malware loader used to download and execute additional payloads on compromised systems. It has also been referred to as Garbage Cleaner and has been observed masquerading as a fake system-cleaning utility, including branding that imitates legitimate cleaning software. The malware is part of the commodity cybercrime loader ecosystem and has been seen both as a standalone PPI loader and as a payload distributed by other malware delivery services such as PrivateLoader, NullMixer, and Amadey-linked campaigns.
GCleaner communicates with command-and-control infrastructure over HTTP, reports installation-related status information, and retrieves additional executables for local execution. Observed samples beacon to remote servers, transmit installation markers associated with BroomCleaner branding, download follow-on binaries, write them to temporary storage, and launch them via standard Windows execution APIs. In at least one analyzed case, the downloaded follow-on payloads were assessed as StealC samples, demonstrating GCleanerβs role as a malware delivery mechanism rather than an end-stage payload.
Distribution has been tied to malicious software-crack and fake-download ecosystems. It has been observed in campaigns using SEO poisoning and lure sites advertising cracked software, where victims are directed to password-protected archives containing installers that deploy multiple malware families. GCleaner has also been associated with fake cleaning-tool lures. Through these ecosystems it has been used alongside or in proximity to families such as Raccoon Stealer, RedLine, SmokeLoader, Vidar, and other commodity malware.
The malware targets Windows systems and is relevant across broad opportunistic victim populations rather than a single vertical. Its operational role is primarily initial payload delivery and staging for financially motivated cybercrime activity.
C2 tracking
Derp observations, rolling seven-day window
Samples
0f78a658b60f0879acccf0933d9ae8a5d2c188e9f16b8e6f7b01bd0cc9b5c4e1 27215e26b312b8b4f8fc51bdcea6741536dafc9267348284e2259e798aed0e4d 3755718db9d33f4aba2563de454d4530a308b41b1096c904102d08e2101f2020 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 738eacc140159cd81dff41dd16c806eb7c0c8391c256f1738d75d0321f77ba2e 76e6367d8123171afa540fe92a3758424ec7d1e029c4e5a3b9771e24fe0085c1 7dcffe29d07d646b361b1bff52dfebd9747e766971d0284c788baaf38631ff5c 85ec743443fe4830daddd95a454fc05b6434adf486a6889134b5d50c29570c9d 9c927df9fdd83af1b57810daa6cc7712a238d31a860bb8d33c6dacb03f53584d b926a44910e4f4d55c53fdc6d9cdbfb043059355d55fb3595a3434bd69b1e7e3 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.