{
  "family": "gaofenquming",
  "sample_count": 1,
  "category": "advanced_threat",
  "description": "<h3>Executive Summary</h3>\nGaofenquming is an intrusive adware family and browser hijacker predominantly targeting users in the Asia-Pacific (APAC) region. It is designed to aggressively monetize infected systems by hijacking web traffic, altering browser configurations, and forcing users to interact with affiliate-linked search portals and advertisements.\n\n<h3>Infection Vector and Technical Behavior</h3>\nGaofenquming relies heavily on software bundling, often piggybacking on the installation of regional freeware, media players, or localized software utilities downloaded from third-party aggregators.\n\nUpon successful installation, Gaofenquming executes a series of unauthorized system modifications:\n<ul>\n<li><strong>Browser Hijacking:</strong> It forcibly alters the default homepage, new tab page, and default search engine across all major web browsers (Chrome, Firefox, Edge, Internet Explorer). The new settings redirect all queries to a customized search portal controlled by the adware operators.</li>\n<li><strong>Registry Persistence:</strong> The adware establishes persistence by modifying the Windows Registry (e.g., `HKCU\\Software\\Microsoft\\Internet Explorer\\Main`) to ensure its preferred homepage is reinstated even if the user attempts to manually change it back.</li>\n<li><strong>Ad Injection:</strong> Gaofenquming injects JavaScript into active browsing sessions, displaying persistent pop-up ads, banners, and sponsored search results that are often highly deceptive or malicious in nature.</li>\n</ul>\n\n<h3>Privacy and Security Risks</h3>\nBeyond the severe degradation of system performance and user experience, Gaofenquming poses a significant privacy risk. It continuously tracks search queries, browsing history, and IP address data, transmitting this telemetry to remote servers for targeted advertising and data brokering.\n\n<h3>Remediation Guidelines</h3>\n<ul>\n<li><strong>Extension Audit:</strong> Manually inspect and remove any unknown or unauthorized extensions from all installed web browsers.</li>\n<li><strong>Complete Browser Reset:</strong> Perform a factory reset of the affected web browsers to clear the hijacked search engine configurations and homepage settings.</li>\n<li><strong>Malware Scanning:</strong> Utilize a reputable EPP/anti-malware solution to perform a deep system scan to remove the underlying executable files, hidden scheduled tasks, and persistent registry keys associated with Gaofenquming.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Adware.Gaofenquming",
    "Hijacker.Gaofenquming",
    "PUP.Gaofenquming"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1566.002",
    "T1176",
    "T1112"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T16:09:08Z",
  "type": "Browser Hijacker",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}