{
  "family": "funmood",
  "sample_count": 1,
  "category": "advanced_threat",
  "description": "<h3>Executive Summary</h3>\nFunmood (often seen as Funmoods Toolbar) is a highly prevalent family of Potentially Unwanted Programs (PUPs) and aggressive Browser Hijackers. Originally marketed as a fun utility providing custom emojis, cursor themes, and wallpapers, its true objective is to forcefully take over the user's web browsers, redirecting all search traffic to affiliate networks to generate illicit ad revenue and harvesting user telemetry.\n\n<h3>Distribution and Technical Behavior</h3>\nFunmood was notoriously distributed via aggressive software bundling. It was frequently hidden within \"free\" software installers, screensavers, or disguised as a necessary plugin update on untrustworthy download portals.\n\nOnce executed, Funmood deeply integrates with installed web browsers:\n<ul>\n<li><strong>Browser Hijacking:</strong> Funmood replaces the browser's default search engine, homepage, and new tab settings (typically routing traffic through `search.funmoods.com`). This redirection allows the operators to intercept queries and serve heavily sponsored, often deceptive, search results.</li>\n<li><strong>Toolbar/BHO Installation:</strong> The software installs a visible toolbar or a hidden Browser Helper Object (BHO) in Internet Explorer and extensions in Chrome/Firefox. These components track the user's browsing history and inject disruptive banner ads and pop-ups into legitimate websites.</li>\n<li><strong>Persistence:</strong> Funmood utilizes Windows Registry modifications to ensure its toolbar is loaded every time the browser starts, and it actively resists user attempts to change the homepage back to its default state.</li>\n</ul>\n\n<h3>Risk Assessment</h3>\nWhile Funmood does not actively encrypt files or steal banking credentials, it introduces massive operational friction and severely degrades the user experience. The constant tracking of search habits presents a privacy risk, and the injected advertisements are frequently served by low-reputation networks, increasing the likelihood of \"malvertising\" attacks.\n\n<h3>Mitigation and Removal Strategies</h3>\n<ul>\n<li><strong>Endpoint Scanning:</strong> Utilize a reputable enterprise-grade anti-malware solution to perform a system scan, targeting the Funmood executables and persistent registry keys used to maintain its hold on the browser.</li>\n<li><strong>Browser Remediation:</strong> Manually inspect and remove the Funmoods extension/toolbar from all installed web browsers. Perform a complete factory reset of the browsers to clear the hijacked search settings and BHOs.</li>\n<li><strong>Application Control:</strong> Enforce strict application whitelisting policies to prevent standard users from executing unapproved \"customization\" software that is the primary vector for this hijacker.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Adware.Funmoods",
    "PUP.Funmood",
    "BrowserModifier:Win32/Funmoods"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1566.002",
    "T1176",
    "T1112",
    "T1547.009"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T17:15:09Z",
  "type": "Browser Hijacker / Adware",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}