{
  "family": "goobzo",
  "sample_count": 1,
  "category": "trojan",
  "description": "<h3>Executive Summary</h3>\nGoobzo is a widespread family of Adware and Browser Hijackers engineered to aggressively monetize an infected user's web browsing activity. By forcefully altering browser configurations and injecting intrusive advertisements, Goobzo significantly degrades system performance and poses a severe threat to end-user privacy within enterprise environments.\n\n<h3>Distribution and Technical Behavior</h3>\nGoobzo is almost exclusively distributed via deceptive software bundling. It is frequently hidden within \"free\" software installers, PDF converters, or media players downloaded from untrustworthy, third-party software portals.\n\nOnce executed, Goobzo deeply integrates with the operating system and installed web browsers (Google Chrome, Firefox, Edge). Its core behaviors include:\n<ul>\n<li><strong>Browser Hijacking:</strong> Goobzo forcefully alters the browser's default search engine, homepage, and new tab settings. All search traffic is redirected through an affiliate-linked search portal controlled by the adware operators to generate illicit ad revenue.</li>\n<li><strong>Traffic Interception and Injection:</strong> The software frequently installs malicious browser extensions or a local proxy server to intercept unencrypted web traffic, overlaying legitimate websites with pop-ups, pop-unders, and sponsored in-text hyperlinks.</li>\n<li><strong>Data Harvesting:</strong> It continuously tracks the user's browsing history, search queries, and clickstreams, transmitting this telemetry to remote servers to serve highly targeted advertisements.</li>\n</ul>\n\n<h3>Risk Assessment</h3>\nWhile Goobzo does not actively encrypt files or steal credentials like a banking trojan, it introduces massive operational friction. Furthermore, the injected advertisements are frequently served by low-reputation ad networks, dramatically increasing the likelihood of \"malvertising\" attacks that can lead to severe secondary infections.\n\n<h3>Mitigation and Removal Strategies</h3>\n<ul>\n<li><strong>Endpoint Scanning:</strong> Utilize a reputable enterprise-grade anti-malware solution to perform a deep system scan, targeting the Goobzo executables, hidden scheduled tasks, and persistent registry keys used to maintain its hold on the browser.</li>\n<li><strong>Browser Remediation:</strong> Manually inspect and remove any unknown or unauthorized extensions from all installed web browsers. Perform a complete factory reset of the browsers to clear the hijacked proxy and search settings.</li>\n<li><strong>Application Control:</strong> Enforce strict application whitelisting policies to prevent standard users from executing unapproved software installers that are the primary vector for this adware.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Adware.Goobzo",
    "PUP.Goobzo",
    "BrowserModifier.Goobzo"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1566.002",
    "T1176",
    "T1112"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T16:35:09Z",
  "type": "Adware",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}