สำ นักงานพัฒนาธุรกรรมทางอิเล็กทรอนิกส์ Electronic Transactions Development Agency Groups Tools Search Statistics Search ↑ Home > List all groups > List all tools > List all groups using tool DIRTCLEANER Threat Group Cards: A Threat Actor Encyclopedia Tool: DIRTCLEANER Names DIRTCLEANER CCleaner Backdoor Category Malware Type Loader Description (FireEye) The compromised CCleaner update (which we call DIRTCLEANER) is believed to download a second-stage loader (MD5: 748aa5fcfa2af451c76039faf6a8684d) that contains a 32-bit and 64-bit COLDJAVA DLL payload. Information Malpedia Last change to this tool card: 13 May 2020 Download this tool card in JSON format All groups using tool DIRTCLEANER Changed Name Country Observed APT groups APT 41 2012-Jul 2025 1 group listed (1 APT, 0 other, 0 unknown) Infrastructure and Security Department Electronic Transactions Development Agency Follow us on Report incidents +66 (0)2-123-1227 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=eea1ecd4-bc9f-49cf-8f31-e746c1eb051d Page 1 of 2 helpdesk@etda.or.th https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=eea1ecd4-bc9f-49cf-8f31-e746c1eb051d Page 2 of 2