{
  "family": "awangba",
  "sample_count": 1,
  "category": "ransomware",
  "description": "<h3>Executive Summary</h3>\nAwangba (often detected as Adware.Awangba or PUP.Wangba) is an aggressive, Chinese-origin Adware and Potentially Unwanted Program (PUP) designed to heavily monetize infected systems. It achieves this by hijacking web browser settings, forcefully injecting unauthorized advertisements, and tracking user browsing habits to generate fraudulent affiliate revenue. It is notorious for its persistent and difficult-to-remove components.\n\n<h3>Infection Vector and Technical Capabilities</h3>\nAwangba primarily infiltrates systems via deceptive software bundling. It is frequently packaged with \"freeware\" applications, game modifications, or pirated software downloaded from untrustworthy, often Asian-hosted, file-sharing websites. The installation process utilizes deceptive \"Dark Patterns\" to hide the adware's deployment.\n\nOnce installed, Awangba aggressively degrades the user experience:\n<ul>\n<li><strong>Browser Hijacking:</strong> It forcibly alters the default homepage, new tab page, and search engine in major web browsers (Chrome, Edge, Firefox), redirecting all traffic through attacker-controlled affiliate links to artificially inflate ad impressions.</li>\n<li><strong>Intrusive Ad Injection:</strong> The adware actively modifies the HTML of legitimate websites visited by the user, overlaying the page with intrusive pop-ups, banner ads, and \"sponsored\" links that completely disrupt normal web browsing.</li>\n<li><strong>Aggressive Persistence:</strong> Awangba is known for establishing deep persistence mechanisms. It often installs malicious browser extensions protected by Windows Group Policy Objects (GPOs) to prevent user removal, and it modifies registry `Run` keys to ensure the adware background processes launch automatically upon every system boot.</li>\n</ul>\n\n<h3>Threat Assessment</h3>\nWhile Awangba is not typically destructive like a file-encrypting ransomware, it causes severe operational disruption. The constant rendering of injected ads consumes significant CPU and RAM, leading to severe browser latency and system instability. The persistent tracking of search queries also constitutes a significant privacy violation.\n\n<h3>Incident Response and Remediation</h3>\n<ul>\n<li><strong>Specialized Anti-Malware Scan:</strong> Standard antivirus often struggles to fully remove deep-seated adware. Utilize an enterprise-grade anti-malware solution specifically designed for PUP/Adware removal to target the persistent registry keys and scheduled tasks.</li>\n<li><strong>Group Policy Audit:</strong> IT staff must inspect the local Windows Group Policy settings (specifically for Chrome and Edge) to remove any unauthorized policies that are force-installing the Awangba browser extensions.</li>\n<li><strong>Browser Factory Reset:</strong> To completely eradicate the hijacking components and tracking cookies, all installed web browsers on the infected endpoint must undergo a full factory reset.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Adware.Awangba",
    "PUP.Wangba",
    "BrowserHijacker.Awangba"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1562.001",
    "T1185",
    "T1112"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-02T07:27:02Z",
  "type": "Adware / PUP",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}