Gaofenquming
Overview
Executive Summary
Gaofenquming is an intrusive adware family and browser hijacker predominantly targeting users in the Asia-Pacific (APAC) region. It is designed to aggressively monetize infected systems by hijacking web traffic, altering browser configurations, and forcing users to interact with affiliate-linked search portals and advertisements.Infection Vector and Technical Behavior
Gaofenquming relies heavily on software bundling, often piggybacking on the installation of regional freeware, media players, or localized software utilities downloaded from third-party aggregators. Upon successful installation, Gaofenquming executes a series of unauthorized system modifications:- Browser Hijacking: It forcibly alters the default homepage, new tab page, and default search engine across all major web browsers (Chrome, Firefox, Edge, Internet Explorer). The new settings redirect all queries to a customized search portal controlled by the adware operators.
- Registry Persistence: The adware establishes persistence by modifying the Windows Registry (e.g., `HKCU\Software\Microsoft\Internet Explorer\Main`) to ensure its preferred homepage is reinstated even if the user attempts to manually change it back.
- Ad Injection: Gaofenquming injects JavaScript into active browsing sessions, displaying persistent pop-up ads, banners, and sponsored search results that are often highly deceptive or malicious in nature.
Privacy and Security Risks
Beyond the severe degradation of system performance and user experience, Gaofenquming poses a significant privacy risk. It continuously tracks search queries, browsing history, and IP address data, transmitting this telemetry to remote servers for targeted advertising and data brokering.Remediation Guidelines
- Extension Audit: Manually inspect and remove any unknown or unauthorized extensions from all installed web browsers.
- Complete Browser Reset: Perform a factory reset of the affected web browsers to clear the hijacked search engine configurations and homepage settings.
- Malware Scanning: Utilize a reputable EPP/anti-malware solution to perform a deep system scan to remove the underlying executable files, hidden scheduled tasks, and persistent registry keys associated with Gaofenquming.
Known aliases
Threat reports may refer to this family under multiple names:
MITRE ATT&CK Techniques
This family has been observed using the following ATT&CK techniques: T1566.002 T1176 T1112
Tactical Mitigations
Based on the techniques used by this family, consider the following defensive strategies:
- T1566.002: Inspect email links for known malicious domains and use link-rewriting services for time-of-click analysis.
Generated Detections (Boilerplate)
These YARA and Sigma rules are auto-generated based on the family name and aliases. They must be heavily tuned before deployment in a production environment.
YARA Rule
rule MALWARE_WIN_GAOFENQUMING {
meta:
description = "Detects Gaofenquming (advanced_threat)"
author = "SystemHelpdesk Boilerplate Generator"
date = "2026-07-06"
strings:
$s1 = "gaofenquming" ascii wide nocase
$s2 = "adware.gaofenquming" ascii wide nocase
$s3 = "hijacker.gaofenquming" ascii wide nocase
$s4 = "pup.gaofenquming" ascii wide nocase
condition:
uint16(0) == 0x5a4d and any of them
}Sigma Rule
title: Suspicious Gaofenquming Activity
id: 790dd123c91845096a9a851a14195053
status: experimental
description: Detects generic indicators of the gaofenquming malware family.
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
CommandLine|contains:
- "*gaofenquming*"
- "*adware.gaofenquming*"
- "*hijacker.gaofenquming*"
- "*pup.gaofenquming*"
condition: selection
level: mediumReferences & External Analysis
- Search "gaofenquming" on VirusTotal (External Analysis)
Frequently Asked Questions
How do I remove the Gaofenquming Advanced_Threat from Windows?
Manual removal of Gaofenquming is highly discouraged as it may leave persistence mechanisms intact. We recommend disconnecting the device from the internet and utilizing a professional incident response service or enterprise-grade EDR software to conduct a full forensic sweep.
Is Gaofenquming a virus or a Advanced_Threat?
Gaofenquming is classified as a Advanced_Threat. Unlike traditional viruses that infect files, modern malware like Gaofenquming typically operates as a standalone payload designed to compromise systems, steal data, or deploy secondary stage implants.
What are the main symptoms of a Gaofenquming infection?
Symptoms of Gaofenquming can include unexpected system slowness, unauthorized outbound network traffic to unknown IP addresses, disabled security software, and suspicious background processes running from AppData or Temp directories.
Related Families (Category: advanced_threat)
Explore other malware families in the same category:
Protect Your Network Against Advanced_Threats
Want to prevent Gaofenquming and similar threats from compromising your organization? Read our comprehensive defensive guide: Suspect an Infection? What to do.
Machine-readable
Get this profile as JSON: https://jordanricky1604-ship-it.github.io/malware-families-catalog/api/gaofenquming.json
Ecosystem & Interactive Environments
This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families. The catalog is also published across our ecosystem: Hugging Face, Kaggle, Zenodo, Replit, StackBlitz, CodeSandbox, and CodePen.