typeentityconfidencelowcreated2026-05-30updated2026-08-24malware-familydownloaderinstallerpe

gcleaner

Umbrella label used by MalwareBazaar and OpenCTI for a cluster of Windows droppers / bundlers that drop varied payloads (stealers, miners, PUPs). In this corpus, dropped-by-gcleaner appears across ~29 samples assigned to disparate families (euone, bb5file, uniqfile, us0file, usfile, salatstealer, masslogger, eu0file). This suggests gcleaner is a multi-payload distribution infrastructure rather than a single malware family.

Build Stack

Heterogeneous — observed droppers include Delphi (see euone), .NET, and scripted variants. No consistent compiler fingerprint.

Deployment / TTPs

  • Installation: Often masquerades as system "cleaner" or "optimizer" software.
  • Drop behaviour: Downloads or embeds secondary payloads at runtime.
  • Attribution: Tags overlap with offloader and dropped-by-offloader OpenCTI labels.

Notable Analyses

  • euone — Delphi VCL droplet; lone euone-labelled sample in this corpus.
  • poabu-inno-dropper — Inno Setup 6.7.0 installer masquerading as contact-indexing service, Authenticode-signed with stolen Sectigo cert. dropped-by-gcleaner / mix4.file tags. ^[/intel/analyses/bb3fd6cd4a7ad6fe91cf30362157569837315dec25ec15fc0733b2e9307fa9ce.html]
  • meshcentral-agent-dropper — Go 1.26.2 MeshCentral agent installer distributed via gcleaner pipeline. Two confirmed siblings (90989061, d65f14e5). ^[entities/meshcentral-agent-dropper.md]
  • valetgate — MinGW-w64 C++ RAT (61db1447) with HTTPS REST C2, AES payload decryption, schtasks persistence, and watchdog respawning. Distributed via dropped-by-gcleaner pipeline. Static-only. ^[entities/valetgate.md]
  • unattributed 01372355 — Themida-packed x64 PE with TreeSize masquerade and self-signed Logitech cert, distributed via dropped-by-gcleaner / mix8.file. Static-only. ^[/intel/analyses/013723553a157de6a46952a5e06cbbb7efa2de04e5292a2066cd95e226192ca7.html]
  • See also /intel/analyses/d46e2b499e86af660a5778b64eea5738a5fea32b693dc078b0d2067abf176aec.html — false-positive assessment of a dropped-by-gcleaner-tagged legitimate mspaint.exe (Windows 8.1 RTM). Demonstrates how the gcleaner umbrella label can over-tag benign system binaries when they are bundled in distribution archives.

Capabilities

  • multi-payload-dropper
  • system-optimizer-social-engineering

References

  • OpenCTI label: gcleaner / dropped-by-gcleaner / dropped-by-offloader