{
  "family": "adanti",
  "sample_count": 1,
  "category": "advanced_threat",
  "description": "<h3>Executive Summary</h3>\nAdanti is an aggressive adware family designed to hijack web browsers and inject unsolicited advertisements into the user's browsing experience. It is engineered to generate continuous revenue through pay-per-click (PPC) and pay-per-view (PPV) affiliate schemes, often at the expense of system performance and user privacy.\n\n<h3>Technical Details and Behavior</h3>\nAdanti is typically distributed via deceptive software installers and fake system updates (e.g., fake Adobe Flash Player updates). Once it breaches a system, it installs malicious browser extensions and alters system-wide proxy settings to intercept and manipulate web traffic.\n\nThe core functionality of Adanti revolves around its ability to analyze the content of the web pages a user is visiting and dynamically inject contextually relevant advertisements. This is achieved by executing heavily obfuscated JavaScript within the browser context. Adanti establishes persistence through Windows Services and scheduled tasks, ensuring that if the user attempts to remove the browser extension, the background service will simply reinstall it upon the next reboot.\n\n<h3>Security Implications</h3>\nThe risk posed by Adanti extends beyond mere annoyance. By manipulating network traffic and executing arbitrary scripts within the browser, it creates a vulnerability that can be exploited for cross-site scripting (XSS) attacks or man-in-the-middle (MitM) surveillance. The adware's C2 communications also create unnecessary noise on the network, complicating incident response efforts.\n\n<h3>Remediation and Eradication</h3>\n<ul>\n<li><strong>Proxy Verification:</strong> Inspect and reset the Windows system proxy settings (Internet Options -> Connections -> LAN settings) to ensure traffic is not being maliciously routed.</li>\n<li><strong>Service Removal:</strong> Identify and disable any unauthorized Windows Services associated with Adanti using the Services snap-in (`services.msc`) or the command line (`sc delete`).</li>\n<li><strong>Enterprise Policies:</strong> Utilize Group Policy Objects (GPO) to prevent standard users from modifying critical browser settings or installing unapproved extensions.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Adware.Adanti",
    "PUP.Adanti",
    "Adanti Adware"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1566",
    "T1543.003",
    "T1176"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T16:00:59Z",
  "type": "Adware",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}