{
  "family": "cdnhelper",
  "sample_count": 1,
  "category": "ransomware",
  "description": "<h3>Executive Summary</h3>\nCDNHelper is a family of Adware and Potentially Unwanted Programs (PUPs) engineered to aggressively monetize an infected user's web browsing activity. It often masquerades as a legitimate browser extension or utility designed to \"optimize\" web traffic or improve streaming performance. In reality, it intercepts web traffic, injects intrusive advertisements, and poses a significant threat to end-user privacy.\n\n<h3>Distribution and Technical Behavior</h3>\nCDNHelper is almost exclusively distributed via deceptive software bundling. It is frequently hidden within \"free\" software installers, fake media players, or disguised as a necessary plugin on untrustworthy streaming websites.\n\nOnce executed, CDNHelper deeply integrates with the operating system and installed web browsers. Its core behaviors include:\n<ul>\n<li><strong>Traffic Interception (Proxying):</strong> CDNHelper frequently installs a local proxy server or malicious browser extensions (Chrome, Firefox, Edge). It routes unencrypted web traffic through its own servers, allowing it to inspect and modify the content of web pages in real-time.</li>\n<li><strong>Advertisement Injection:</strong> It overlays legitimate websites with pop-ups, pop-unders, banner ads, and sponsored in-text hyperlinks. It often replaces legitimate advertisements on a webpage with ads from its own affiliate network.</li>\n<li><strong>Data Harvesting and Telemetry:</strong> It continuously tracks the user's browsing history, search queries, and clickstreams, transmitting this telemetry to remote servers to serve highly targeted, albeit unwanted, advertisements.</li>\n</ul>\n\n<h3>Risk Assessment</h3>\nWhile CDNHelper does not actively encrypt files like ransomware, it introduces massive operational friction and severely degrades network performance. Furthermore, the injected advertisements are frequently served by low-reputation ad networks, dramatically increasing the likelihood of \"malvertising\" attacks that can lead to severe secondary infections.\n\n<h3>Mitigation and Removal Strategies</h3>\n<ul>\n<li><strong>Endpoint Scanning:</strong> Utilize a reputable enterprise-grade anti-malware solution to perform a deep system scan, targeting the CDNHelper executables, hidden scheduled tasks, and persistent registry keys used to maintain its hold on the browser.</li>\n<li><strong>Browser Remediation:</strong> Manually inspect and remove any unknown or unauthorized extensions from all installed web browsers. Perform a complete factory reset of the browsers to clear the hijacked proxy and search settings.</li>\n<li><strong>Application Control:</strong> Enforce strict application whitelisting policies to prevent standard users from executing unapproved software installers that are the primary vector for this adware.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Adware.CDNHelper",
    "PUP.CDNHelper",
    "BrowserModifier:Win32/CDNHelper"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1566.002",
    "T1176",
    "T1112"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T16:40:53Z",
  "type": "Adware",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}