Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Extenbro is typically delivered by an unknown bundler along with other potentially unwanted applications.
Once installed, Extenbro will alter the system's DNS settings, replacing the previous addresses with its own in order to prevent the user from reaching online security services. A randomly-named task is used to ensure these setting are reapplied after every reboot. It will then add its own certificate to the system store and alter registry keys to disable IPv6. Extenbro will also alter the Mozilla Firefox user.js file to force Firefox to use this store.
Remediation steps
| Type | Step |
|---|---|
|
As Extenbro prevents security services from accessing the Internet, it is likely that organisations will have to manually alter affected systems DNS settings before attempting to remediate. Please follow the below guidance to do so:
Additionally, to prevent and detect a trojan infection, ensure that:
|
Last edited: 14 February 2020 2:42 pm