{
  "family": "gorillaprice",
  "sample_count": 34,
  "category": "advanced_threat",
  "description": "Adware:Win32/Gorillaprice is a deceptive adware framework and Potentially Unwanted Program (PUA) that silently infiltrates endpoints, typically bundled with freeware, to inject intrusive price-comparison widgets, banner advertisements, and hijack browser settings for affiliate monetization.<br><br><b>What is Gorillaprice?</b><br>To the average user, Gorillaprice is highly visible and deeply frustrating. When browsing shopping sites (like Amazon or eBay), Gorillaprice injects large 'price comparison' pop-ups, often leading to shady third-party vendors. The browser homepage is forcibly changed, and standard websites are flooded with injected banner ads. For security analysts, Gorillaprice operates on the Pay-Per-Install (PPI) model. It leverages deceptive installation tactics and aggressive persistence mechanisms to ensure the user cannot easily revert their browser settings, guaranteeing continued revenue generation.<br><br><b>Infection Vectors & Threat Hunting</b><br>Gorillaprice is almost exclusively distributed via deceptive software bundlers. When a user downloads a free PDF editor or media player from a third-party site, the Gorillaprice wrapper executes first. It employs 'Dark Patterns'—pre-checked boxes hidden behind 'Advanced' menus—to gain technical consent. Upon execution, it installs malicious browser extensions and frequently leverages Windows Group Policy (GPO) settings (`ExtensionInstallForcelist`) to lock the rogue extensions in place. It establishes persistence via Registry Run keys and scheduled tasks.<br><br><b>Forensic Analysis & Impact</b><br>The primary impact is a severely degraded user experience, compromised browsing privacy, and wasted helpdesk resources. Incident responders will observe anomalous HTTP/HTTPS traffic to known ad-tracking networks, particularly when the user navigates to e-commerce sites. EDR logs will show the initial installer attempting to modify browser preference files (e.g., Chrome's `Preferences` JSON file) and establishing unauthorized Group Policies.",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [],
  "enrichment_level": "expert-seo",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1112",
    "T1105",
    "T1176",
    "T1562.001",
    "T1189"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-06-09",
  "mitre_attack_detail": [
    {
      "id": "T1189",
      "name": "Drive-by Compromise",
      "tactic": "Initial Access"
    },
    {
      "id": "T1176",
      "name": "Browser Extensions",
      "tactic": "Persistence"
    },
    {
      "id": "T1112",
      "name": "Modify Registry",
      "tactic": "Defense Evasion"
    },
    {
      "id": "T1562.001",
      "name": "Impair Defenses: Disable or Modify Tools",
      "tactic": "Defense Evasion"
    },
    {
      "id": "T1105",
      "name": "Ingress Tool Transfer",
      "tactic": "Command and Control"
    }
  ],
  "containment_steps": [
    "Quarantine the endpoint to halt the active exfiltration of browsing telemetry and the downloading of further adware modules.",
    "Audit Windows Group Policies and the Registry to remove any forced extension installation policies created by the adware.",
    "Deploy an enterprise adware removal tool (e.g., AdwCleaner) to locate and strip the deeply embedded registry hooks and watchdog services.",
    "Force a complete reset of all installed web browsers to factory defaults to eradicate the rogue extensions and restore the homepage."
  ],
  "what_to_avoid": [
    "Do not rely solely on the browser's 'remove extension' button; Gorillaprice frequently uses GPOs and watchdog services to immediately reinstall itself.",
    "Avoid ignoring the infection; adware tracking data is highly detailed and may expose corporate activities or access to internal portals."
  ],
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}