BonziBuddy is a freeware desktop virtual assistant for Microsoft Windows developed by Bonzi Software, Inc., initially released in 1999. Although marketed as a virtual assistant that could tell jokes and facts, manage downloads, sing songs, and talk to users, it became widely known as adware and spyware. It used Microsoft Agent technology, initially appearing as the Peedy character before being updated in May 2000 to its own purple gorilla character, Bonzi, and used the Sydney text-to-speech voice from the Lernout & Hauspie Microsoft Speech API 4.0 package. High-confidence reporting in the provided content states that BonziBuddy collected user information, reset users' browser homepages to bonzi.com without permission, installed a browser toolbar, tracked user information, and served advertisements. Consumer Reports Web Watch labeled it spyware in 2002 and stated that it contained a backdoor trojan that collected information from users. Trend Micro, Symantec, and Spyware Guide classified it as adware. BonziBuddy was associated with deceptive advertising practices, including banner ads imitating Windows security alerts, and Bonzi Software later faced a class action settlement in 2003 and a 2004 FTC penalty for violating COPPA by collecting personal information from children under 13. The software was discontinued in 2004, with a final release identified in the content as version 4.1 in 2005.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware ... BonziBuddy
A desktop assistant program widely classified as adware and spyware. It collected user information, reset browser homepages, installed a browser toolbar, and served advertisements; reporting also described it as containing a backdoor trojan component.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.