{
  "family": "installcore",
  "sample_count": 1961,
  "category": "pua",
  "description": "<h3>Executive Summary</h3>\nInstallCore is a highly prevalent, aggressive content delivery network (CDN) and installation manager that is universally classified by the cybersecurity industry as a Potentially Unwanted Program (PUP) and Adware. It acts as a wrapper around legitimate software installations, monetizing the \"free\" download by aggressively bundling and silently installing a multitude of unwanted third-party applications, browser hijackers, and tracking cookies onto the user's system.\n\n<h3>Infection Vector and Technical Capabilities</h3>\nInstallCore is encountered when users attempt to download popular freeware (like media players, PDF readers, or Java updates) from third-party, unofficial software aggregators. The downloaded file is not the software itself, but the InstallCore \"wrapper.\"\n\nIts technical operation relies on deception and aggressive installation tactics:\n<ul>\n<li><strong>Deceptive UI/UX (Dark Patterns):</strong> The InstallCore installer uses confusing language, pre-checked boxes, and misleading \"Next\" buttons to trick the user into \"agreeing\" to install the bundled adware.</li>\n<li><strong>Aggressive Bundling:</strong> A single InstallCore wrapper can silently install 5 to 10 different PUPs simultaneously. This typically includes browser hijackers (changing the default search engine), desktop weather widgets, fake system optimizers, and extensive tracking software.</li>\n<li><strong>Evasion and Anti-Analysis:</strong> Advanced versions of InstallCore employ techniques to evade detection by security researchers. They may refuse to execute or serve different (clean) payloads if they detect they are running in a Virtual Machine (VMware) or an automated sandbox.</li>\n</ul>\n\n<h3>Threat Assessment</h3>\nInstallCore is a high-impact nuisance and a moderate security risk. While it does not typically deploy ransomware, it severely degrades system performance, compromises browser security (via hijacking), and exposes the user to potentially malicious third-party advertisements (malvertising). It also generates massive IT helpdesk overhead as users complain of \"slow PCs\" and \"pop-ups.\"\n\n<h3>Incident Response and Remediation</h3>\n<ul>\n<li><strong>PUP-Specific Scanning:</strong> Standard enterprise antivirus often ignores InstallCore because the user technically \"agreed\" to the installation via the EULA. A dedicated anti-malware solution configured to aggressively target PUPs is required to remove the deeply embedded adware components.</li>\n<li><strong>Comprehensive Browser Reset:</strong> The most damaging aspect of InstallCore is the browser hijacking. IT must thoroughly reset all web browsers to default settings, remove all unknown extensions, and delete all tracking cookies.</li>\n<li><strong>Software Restriction Policies:</strong> To prevent future infections, implement AppLocker or Software Restriction Policies (SRP) to prevent users from executing unapproved `.exe` installers downloaded from the internet.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "PUP.Optional.InstallCore",
    "Adware.InstallCore",
    "OSX/InstallCore"
  ],
  "enrichment_level": "documented_reference_only",
  "faq": [
    {
      "@type": "Question",
      "name": "Where can I learn more about installcore?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Refer to the linked MITRE ATT&CK technique pages, which document the behaviors associated with this family."
      }
    }
  ],
  "faq_count": 1,
  "mitre_attack": [
    "T1562.001",
    "T1112",
    "T1185"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-02T09:01:15Z",
  "type": "Adware / PUP",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}