{
  "family": "iwin",
  "sample_count": 1,
  "category": "advanced_threat",
  "description": "<h3>Executive Summary</h3>\niWin (often detected as Adware.iWin or PUP.iWin) is a widespread family of Adware and Potentially Unwanted Programs (PUPs). It is historically associated with the bundled installation of \"free\" casual games from the iWin portal. While the games themselves may function, the bundled software aggressively monetizes the user's web browsing activity by injecting intrusive advertisements and altering browser configurations, degrading system performance and user privacy.\n\n<h3>Distribution and Technical Behavior</h3>\niWin adware is almost exclusively distributed via deceptive software bundling. When a user downloads a free game from the iWin portal or affiliated third-party sites, the installer uses pre-checked boxes and confusing EULAs to silently install secondary adware components.\n\nOnce executed, the iWin adware integrates with the operating system and web browsers. Its core behaviors include:\n<ul>\n<li><strong>Browser Hijacking:</strong> The adware forces changes to the browser's default search engine, homepage, and new tab settings. All search traffic is redirected through an affiliate-linked search portal (often heavily branded) controlled by the adware operators to generate illicit ad revenue.</li>\n<li><strong>Advertisement Injection:</strong> It installs browser extensions or local proxies to overlay legitimate websites with pop-ups, pop-unders, banner ads, and sponsored in-text hyperlinks, severely disrupting the user experience.</li>\n<li><strong>Data Harvesting:</strong> The adware continuously tracks the user's browsing history, search queries, and clickstreams, transmitting this telemetry to remote servers to serve highly targeted advertisements.</li>\n</ul>\n\n<h3>Risk Assessment</h3>\nWhile iWin adware does not actively encrypt files or steal banking credentials, it introduces significant operational friction in enterprise environments. Furthermore, the injected advertisements are frequently served by low-reputation ad networks, increasing the likelihood of \"malvertising\" attacks that can lead to severe secondary infections.\n\n<h3>Mitigation and Removal Strategies</h3>\n<ul>\n<li><strong>Endpoint Scanning:</strong> Utilize a reputable enterprise-grade anti-malware solution to perform a deep system scan, targeting the iWin executables, hidden scheduled tasks, and persistent registry keys used to maintain its hold on the browser.</li>\n<li><strong>Browser Remediation:</strong> Manually inspect and remove any unknown or unauthorized extensions from all installed web browsers. Perform a complete factory reset of the browsers to clear the hijacked proxy and search settings.</li>\n<li><strong>Application Control:</strong> Enforce strict application whitelisting policies to prevent standard users from downloading and executing unapproved casual games and their associated, untrusted software installers.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Adware.iWin",
    "PUP.iWin",
    "BrowserModifier:Win32/iWin"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1566.002",
    "T1176",
    "T1112"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T16:40:53Z",
  "type": "Adware",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}