Regarding Cisco Talos and CCleaner lies

cruelsister

Level 42
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,147
Hi guys! This one is too funny (absolutely pathetic) to let slide:

Those that followed the CCleaner malware story from day 1 may remember that Cisco stated that the CCleaner malware was discovered while beta testing one of their security products. Although that original blog was been removed, it was paraphrased in this article: https://arstechnica.com/information...d-in-legitimate-software-updates-to-ccleaner/

"In a blog post this morning, Cisco Talos Intelligence's Edmund Brumaghin, Ross Gibb, Warren Mercer, Matthew Molyett, and Craig Williams reported that Talos had detected the malware during beta testing of a new exploit-detection technology."

Turns out that was a total lie- both Piriform and Cisco were notified by a company called Morphisec on September 12th. Cisco then did a little look-see and notified Avast 2 days later, then took public credit for the discovery on September 18th.

Apparently (and understandably) Morphisec got pissed and now Cisco has redacted the original post of September 18th (somewhat) to include this :"Update 9/19: This issue was discovered and reported by both Morphisec and Cisco in separate in-field cases and reported separately to Avast" and the Cisco beta testing drivel was deleted.

Finally, even Morphisec was also deceptive in this as the original indicator of compromise (the Outbound connection to 216.whatever) was discovered by a user of their product that happened to monitor unusual Outbound connections on their system. But you will still see some nebulous reference to a magic dll from which all was made clear.

One can't trust anyone anymore, can one?
 

L S

Level 5
Verified
Well-known
Jul 16, 2014
215
FROM AVAST on: September 18. 2017. 11:13:31 PM :
BTW, I have to say I was quite disappointed by the approach taken by the Cisco Talos team who appears to be trying to use information about this incident to drive marketing activities and piggyback on the case to increase the visibility of their upcoming product. And, I should probably also say that it wasn't Cisco who first notified us about the problem. The threat was first discovered and reported to us by researchers in a security company called Morphisec (thank you!). The threat was real, but to the best of our knowledge, it was fortunately mitigated before it could do any harm.
 

Weebarra

Level 17
Verified
Top Poster
Well-known
Apr 5, 2017
836
And so it all comes out in the wash as they say. Totally underhand tactics from Cisco who obviously thought they could "cash in" on the fear and panic of consumers. Morphisec should have also come clean and hailed the "user" for his/her detection :rolleyes:
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top