{
  "family": "sokuxuan",
  "sample_count": 1,
  "category": "ransomware",
  "description": "<h3>Executive Summary</h3>\nSokuxuan is an aggressive Adware and Potentially Unwanted Program (PUP) designed to monetize infected systems. It achieves this by hijacking web browser settings, forcefully injecting unauthorized advertisements, and tracking user browsing habits to generate fraudulent affiliate revenue. It is notorious for its persistent and difficult-to-remove components.\n\n<h3>Infection Vector and Technical Capabilities</h3>\nSokuxuan primarily infiltrates systems via deceptive software bundling. It is frequently packaged with \"freeware\" applications, game modifications, or pirated software downloaded from untrustworthy file-sharing websites. The installation process utilizes deceptive \"Dark Patterns\" to hide the adware's deployment.\n\nOnce installed, Sokuxuan aggressively degrades the user experience:\n<ul>\n<li><strong>Browser Hijacking:</strong> It forcibly alters the default homepage, new tab page, and search engine in major web browsers (Chrome, Edge, Firefox), redirecting all traffic through attacker-controlled affiliate links to artificially inflate ad impressions.</li>\n<li><strong>Intrusive Ad Injection:</strong> The adware actively modifies the HTML of legitimate websites visited by the user, overlaying the page with intrusive pop-ups, banner ads, and \"sponsored\" links that completely disrupt normal web browsing.</li>\n<li><strong>Aggressive Persistence:</strong> Sokuxuan is known for establishing persistence mechanisms. It often installs malicious browser extensions and modifies registry `Run` keys to ensure the adware background processes launch automatically upon every system boot.</li>\n</ul>\n\n<h3>Threat Assessment</h3>\nWhile Sokuxuan is not typically destructive like a file-encrypting ransomware, it causes severe operational disruption. The constant rendering of injected ads consumes significant CPU and RAM, leading to severe browser latency and system instability. The persistent tracking of search queries also constitutes a significant privacy violation.\n\n<h3>Incident Response and Remediation</h3>\n<ul>\n<li><strong>Specialized Anti-Malware Scan:</strong> Standard antivirus often struggles to fully remove adware. Utilize an enterprise-grade anti-malware solution specifically designed for PUP/Adware removal to target the persistent registry keys and scheduled tasks.</li>\n<li><strong>Group Policy Audit:</strong> IT staff must inspect the local Windows Group Policy settings (specifically for Chrome and Edge) to remove any unauthorized policies that are force-installing the browser extensions.</li>\n<li><strong>Browser Factory Reset:</strong> To completely eradicate the hijacking components and tracking cookies, all installed web browsers on the infected endpoint must undergo a full factory reset.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Adware.Sokuxuan",
    "PUP.Sokuxuan",
    "BrowserHijacker.Sokuxuan"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1562.001",
    "T1185",
    "T1112"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-02T07:28:51Z",
  "type": "Adware / PUP",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}