MonaRonaDona is a Microsoft Windows browser hijacker and scam-oriented malware threat, also identified as TROJ_MONAGRAY.A and associated in the content with the Vundo trojan family. It relies primarily on social engineering rather than destructive functionality, displaying pop-ups or alert messages that falsely claim the victim’s system is infected. A cited warning begins, "Hi, My name is MonaRonaDona. I am a Virus & I am here to Wreck Your PC," and is intended to frighten users into searching for a remedy, which can redirect them to malicious websites or bogus products. The malware is linked to rogue security software including Unigray Anti-Virus and Registry Clean Fix, and is usually downloaded through the Unigray Anti-Virus program or advertisements for Registry Clean Fix. The content states it can remain inactive and evade antivirus detection at times, surfacing mainly through scare messages. Observed system changes include creation of the registry keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MonaRonaDona and HKEY_LOCAL_MACHINE\SOFTWARE\MonaRonaDona.com, and modification of HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Window Title, HKEY_CURRENT_USER\Software\Microsoft\Outlook Express\Window Title, HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window Title, HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr, and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr. The origin is listed as unknown.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
2008 Agent.BTZ Asprox Conficker Fun.exe Hupigon Mariposa MonaRonaDona OpenCandy
A Windows browser hijacker/trojan that uses fake infection alerts and social engineering popups to scare users into searching for a remedy, leading them to malicious or bogus websites. It is associated with rogue programs such as Registry Clean Fix and Unigray Anti-Virus and may disable Task Manager via registry changes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.