{
  "family": "tongji",
  "sample_count": 1,
  "category": "ransomware",
  "description": "<h3>Executive Summary</h3>\nTongji is a family of Adware, Spyware, and Potentially Unwanted Programs (PUPs), frequently originating from Chinese software markets. The term \"Tongji\" translates roughly to \"statistics\" or \"analytics.\" While sometimes bundled with legitimate applications to collect usage telemetry, Tongji frequently crosses the line into malicious territory by aggressively tracking user behavior, intercepting web traffic, and serving intrusive advertisements without informed consent.\n\n<h3>Distribution and Technical Behavior</h3>\nTongji is almost exclusively distributed via deceptive software bundling, commonly hidden within freeware, media players, or game client installers popular in the East Asian market.\n\nOnce active, Tongji integrates deeply into the operating system and web browsers. Its core behaviors include:\n<ul>\n<li><strong>Aggressive Telemetry:</strong> Tongji continuously tracks the user's browsing history, search queries, application usage, and sometimes keystrokes. This data is aggregated and transmitted to remote analytics servers in plaintext or using weak encryption.</li>\n<li><strong>Traffic Interception:</strong> The software frequently installs a local proxy server or malicious browser extensions to intercept web traffic, overlaying legitimate websites with intrusive pop-ups, pop-unders, and sponsored content.</li>\n<li><strong>Browser Hijacking:</strong> It forcibly alters the default search engine, homepage, and new tab settings to redirect all traffic through affiliate-linked portals controlled by the adware operators.</li>\n</ul>\n\n<h3>Risk Assessment</h3>\nWhile Tongji is not inherently destructive (it does not encrypt files like ransomware), it introduces severe privacy and operational risks. The massive amount of telemetry collected violates enterprise privacy policies, and the injected advertisements are frequently served by low-reputation ad networks, increasing the likelihood of \"malvertising\" and secondary malware infections.\n\n<h3>Mitigation and Removal Strategies</h3>\n<ul>\n<li><strong>Endpoint Scanning:</strong> Utilize a reputable enterprise-grade anti-malware solution to perform a deep system scan, targeting the Tongji executables, hidden scheduled tasks, and persistent registry keys used for tracking.</li>\n<li><strong>Browser Remediation:</strong> Manually inspect and remove any unknown or unauthorized extensions from all installed web browsers. Perform a complete factory reset of the browsers to clear hijacked proxy and search settings.</li>\n<li><strong>Application Control:</strong> Enforce strict application whitelisting policies to prevent standard users from executing unapproved software installers that frequently bundle this type of spyware.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Adware.Tongji",
    "Spyware.Tongji",
    "PUP.Tongji"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1566.002",
    "T1176",
    "T1112",
    "T1056"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T16:31:29Z",
  "type": "Adware",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}