HomeSecurityAvast: Hackers breached internal network by hacking VPN profiles

Avast: Hackers breached internal network by hacking VPN profiles

Cybersecurity software company Avast has revealed that its internal network was breached by hackers. Avast

The company said the attack was likely aimed at introducing malware into its CCleaner software. A similar incident occurred in 2017.

How did the breach occur?

According to Avast, hackers compromised the VPN credentials of an employee of the company. In doing so, they gained access to an account that was not protected.

The company discovered the breach on September 23. It immediately launched an investigation and found evidence indicating that the attackers had been targeting the company's systems since May 14, 2019.

“The user whose credentials were compromised did not have domain administrator privileges. However, through a successful privilege escalation attack, the attacker was able to gain administrator privileges,” said Jaya Baloo, Avast’s information security manager.

According to Baloo, the company left the compromised VPN profile active to monitor the attacker's activities.

This lasted until October 15, when the company released a new updated version of CCleaner.

Additionally, Avast changed the digital certificate it used for CCleaner updates. The company felt this change was necessary in case hackers managed to obtain the old certificate during the network breach

Avast: Hackers breached internal network by hacking VPN profiles

"Having taken all these precautions, we are confident that CCleaner users are protected and not affected," Baloo said

The company, based in the Czech Republic, is working with the police, the Czech intelligence agency, Security Information Service (BIS), and a private company to investigate the breach.

Avast believes the attackers were experienced hackers but is not sure if they are the same group that attacked the company in 2017.

"From the evidence we have gathered so far, it is clear that this was an extremely sophisticated attack against us that was intended to leave no trace of the attacker. The attackers proceeded with extreme caution to avoid detection," Baloo said.

The investigation is ongoing. Avast said it would update if it learns anything new. In 2017, it had released several updates about the breach and was praised for speaking openly and in detail about the matter.

In 2017, attackers planted malware in CCleaner by compromising a account . According to Avast, approximately 2.27 million users had downloaded the compromised CCleaner software.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS