Hackers broke into the Piriform (now owned by Avast) system and modified the CCleaner program to include a malicious program designed to direct computers to get instructions from servers under the hacker’s control.

A version of CCleaner downloaded in August and September included remote administration tools that tried to connect to several unregistered web pages, presumably to download additional unauthorised programs, security researchers at Cisco’s Talos unit said.

In a blog post, Piriform confirmed that two programs released in August were compromised. It advised users of CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 to download new versions. A spokeswoman said that 2.27 million users had downloaded the August version of CCleaner while only 5,000 users had installed the compromised version of CCleaner Cloud.

Piriform said that Avast, its new parent company, had uncovered the attacks on 12th September. A new, uncompromised version of CCleaner was released the same day and a clean version of CCleaner Cloud was released on 15th September, it said.

Please be aware that CCleaner is NOT a tool used by New World IT and would have not been installed by us. However, we are aware that some of our customers use this program, so please ensure you manually update it as soon as possible to ensure your system is not compromised.