{
  "family": "searchsetter",
  "sample_count": 1,
  "category": "advanced_threat",
  "description": "<h3>Executive Summary</h3>\nSearchSetter is a prevalent family of Potentially Unwanted Programs (PUPs) and aggressive Browser Hijackers engineered to rapidly monetize an infected user's web browsing activity. It intercepts web traffic, forcefully alters core browser configurations across all major platforms, and injects intrusive advertisements, posing a significant threat to end-user privacy and degrading network performance.\n\n<h3>Distribution and Technical Behavior</h3>\nSearchSetter is almost exclusively distributed via deceptive software bundling. It is frequently hidden within \"free\" software installers, fake media players, or disguised as a necessary system utility downloaded from untrustworthy, third-party software portals.\n\nOnce executed, SearchSetter deeply integrates with the operating system and installed web browsers. Its core behaviors include:\n<ul>\n<li><strong>Browser Hijacking:</strong> SearchSetter alters the browser's default search engine, homepage, and new tab settings. All search traffic is redirected through an affiliate-linked search portal controlled by the adware operators to generate illicit ad revenue. It often achieves this by deploying persistent Group Policy objects or altering the browser's shortcut `.lnk` files.</li>\n<li><strong>Traffic Interception and Injection:</strong> The software frequently installs malicious browser extensions or a local proxy server to intercept unencrypted web traffic. It overlays legitimate websites with disruptive pop-ups, pop-unders, banner ads, and sponsored in-text hyperlinks.</li>\n<li><strong>Data Harvesting:</strong> It continuously tracks the user's browsing history, search queries, and clickstreams, transmitting this telemetry to remote servers to serve highly targeted advertisements.</li>\n</ul>\n\n<h3>Risk Assessment</h3>\nWhile SearchSetter does not actively encrypt files or steal banking credentials, it introduces massive operational friction. Furthermore, the injected advertisements and hijacked search results are frequently served by low-reputation ad networks, dramatically increasing the likelihood of \"malvertising\" attacks that can lead to severe secondary infections.\n\n<h3>Mitigation and Removal Strategies</h3>\n<ul>\n<li><strong>Endpoint Scanning:</strong> Utilize a reputable enterprise-grade anti-malware solution to perform a deep system scan, targeting the SearchSetter executables, hidden scheduled tasks, and persistent registry keys used to maintain its hold on the browser.</li>\n<li><strong>Browser Remediation:</strong> Manually inspect and remove any unknown or unauthorized extensions from all installed web browsers. Crucially, check all browser shortcut properties to ensure the target path has not been appended with a malicious URL. Perform a complete factory reset of the browsers.</li>\n<li><strong>Application Control:</strong> Enforce strict application whitelisting policies to prevent standard users from executing unapproved software installers that are the primary vector for this hijacker.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Adware.SearchSetter",
    "PUP.SearchSetter",
    "BrowserModifier:Win32/SearchSetter"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1566.002",
    "T1176",
    "T1112",
    "T1547.009"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T17:08:11Z",
  "type": "Browser Hijacker",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}