As cited
Copy frozen at (site build).
threat intel
Chromium extension uses AI‑related branding to redirect browser search
Microsoft Threat Intelligence identified a malicious Chromium extension that impersonated Perplexity AI to trick users into installation, with the primary goal of intercepting search queries and collecting browsing data. The extension used Manifest Version 3 capabilities and declarativeNetRequest rules to transparently redirect Omnibox queries through attacker-controlled infrastructure while maintaining the appearance of legitimate search results. Google removed the extension following responsible disclosure, and researchers noted that threat actors increasingly leverage AI-related branding as a social engineering vector to increase campaign success rates.
Why it matters: If your users install this extension, their search queries and typed characters are intercepted and sent to attacker infrastructure, enabling profiling, advertising targeting, or downstream data misuse with elevated privacy risk.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Chromium extension uses AI‑related branding to redirect browser search
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Chromium extension uses AI‑related branding to redirect browser search
Microsoft Threat Intelligence identified a malicious Chromium extension that impersonates the Artificial Intelligence (AI)‑powered answer engine Perplexity AI to hijack browser search traffic. The extension, using Manifest Version 3 (MV3) and declarativeNetRequest (DNR) rules, forwards full queries and real‑time suggestions to an attacker‑controlled domain (perplexity-ai[.]online) before sending users to legitimate search providers, enabling data collection without obvious redirection. Google has removed the extension from its store, but the incident shows how threat actors abuse trusted AI branding and privileged extension access to conduct stealthy search interception, prompting organizations to review extension policies and user training.
Why it matters: Organizations that allow Chromium extensions are affected because the extension can silently capture search queries and browsing data, requiring immediate review of extension controls and user awareness.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Chromium extension uses AI‑related branding to redirect browser search
Microsoft Threat Intelligence identified a malicious Chromium extension that impersonates the Artificial Intelligence (AI)‑powered answer engine Perplexity AI to hijack browser search traffic. The extension, using Manifest Version 3 (MV3) and declarativeNetRequest (DNR) rules, forwards full queries and real‑time suggestions to an attacker‑controlled domain (perplexity-ai[.]online) before sending users to legitimate search providers, enabling data collection without obvious redirection. Google has removed the extension from its store, but the incident shows how threat actors abuse trusted AI branding and privileged extension access to conduct stealthy search interception, prompting organizations to review extension policies and user training.
Why it matters: Organizations that allow Chromium extensions are affected because the extension can silently capture search queries and browsing data, requiring immediate review of extension controls and user awareness.
- Source published
- First seen by Cybersecurity Tracker