Dragon Angel Malicious Browser Extension

What is Dragon Angel extension?
Malicious extension Dragon Angel hijacks web browser

Dragon Angel is a browser extension that functions as a hijacker malware. It redirects users to promoted search engines or websites. These redirects ruin the process of browsing and can lead to irrelevant or potentially harmful content or malware distribution.

Dragon Angel Overview

Dragon Angel is a malicious browser extension that can appear in Chrome browsers. It usually appears as a result of adware activity on the system. For example, unwanted programs like Chromstera or Chromnius after installation can offer this extension to the main browser. Users complain about it continuously appearing unless the source of the problem – the malignant browser – is removed.

Dragon Angel screenshot
Dragon Angel browser plugin

The purpose for such plugins is search query redirection. Frauds who stand behind it force every single search request that you do to go through their servers. By forming a digital fingerprint of their victims, they earn money after selling it to third parties. I’ve did a comprehensive analysis of Dragon Angel, and found a couple of really interesting details – so read on.

Dragon Angel Detailed Analysis

Dragon Angel appears on your device due to the activity of unwanted software. It is often the result of potentially unwanted software that comes bundled with freeware or software cracks. Although most installers allow you to cancel installing additional software, unscrupulous developers may remove this option.

Search Redirects

Once installed, the extension changes the homepage and some browser settings. It also forcibly redirects all search queries through Dragonboss search engine. It eventually ends up on a legit search engine page, usually Yahoo or Bing, but during these redirections, the said search engine will collect the info about your request. Also, the search results after such a multi-step operation are different from what you would get after a direct request to the search systems.

Malicious ad screenshot
Another malicious extension that Dragon Angel promotes in its redirections

What this means is the victims will see promotions instead of relevant search results. These promos mostly contain sponsored websites – gambling, adult sites or marketplaces who paid for the ads. At the same time, this advertising can lead to phishing websites or malware downloading pages.

Difficulties With Removal

The biggest problem for the average user is that Dragon Angel uses self-defense measures. After installation, the malware modifies registry settings to disable the ability to remove extensions from the browser or change homepage settings. This eventually leads to the infamous “Managed by Your Organization” error in Chrome, and complete inability to remove the extension.

According to the feedback from users who have encountered this plugin, the severity of this problem forces users to reset their PCs. This is the ultimate solution, but it will result in data loss, and feels like hunting sparrows with a tank gun. Fortunately, I have a solution to that problem without data loss. We will discuss it next.

Not by Dragon Angel Alone

During the analysis, I found other extensions from this “developer” called Dragon Honey and Dragon Search. All of them share the same logo, and the same purpose – redirecting user queries through their own search engine. However, this is not the last finding of my research.

The exact same “developer” has another project called Chromnius Browser. It is a browser based on Chromium core, obviously, and does not feature any remarkable qualities. Promotions say that Chromnius is a Web browser that provides better security while browsing online by blocking pop-ups and tracker cookies. Though a closer analysis clearly shows that Chromnius is just yet another adware that tries to look as web browser. It can infect other browsers, send pop-up notifications without user concent and redirect search queries.

How To Remove Dragon Honey

First, I strongly recommend scanning your device for malware. This will neutralize software that modifies system settings. To do this, download GridinSoft Anti-Malware and run a full scan. This will find the malware that initiates browser manipulation. In addition, GridinSoft Anti-Malware allows you to reset your web browser settings entirely in one click. This is especially useful if previous methods have failed.

Dragon Angel Malicious Browser Extension

Next, if you see this “Managed by your organisation” message when opening the browser menu in Google Chrome, there are two ways to remove Dragon Honey; we will look at them now. The first one is automatic and will work for most users. To regain control of the browser, you must follow these instructions to download the file and run it as an administrator. This will remove the entry from the registry, which will not allow you to change the browser settings.

The second method involves all the same, only in manual mode. To do this, press Windows + R on your keyboard, type “regedit“, and select the OK button

regedit

Copy the following path and paste it into the address bar, and press Enter:

Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome

Chrome folder in the regedit

Select the Chrome key from the left pane of your Registry Editor. Right-click on the Chrome policy you want to remove and select Delete.

By Stephanie Adlam

I write about how to make your Internet browsing comfortable and safe. The modern digital world is worth being a part of, and I want to show you how to do it properly.

Leave a comment

Your email address will not be published. Required fields are marked *