Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious AI Extension Hijacks Search Data

Malicious AI Extension Hijacks Search Data

Posted on June 30, 2026 By CWS

A deceptive browser extension, masquerading as the widely recognized AI tool Perplexity AI, has been discovered hijacking user search data and browser signals. This incident highlights the vulnerability of trusted brand names being exploited to compromise user privacy.

The extension, titled “Search for perplexity ai,” mimicked a legitimate AI tool to evade detection by users. It specifically targeted browsers built on the Chromium framework, modifying the default search settings immediately upon installation.

How the Malicious Extension Operated

Once installed, the extension rerouted user searches through its own servers before reaching search engines like Google or Bing. This seamless operation ensured that users remained unaware of the data interception occurring during their browsing sessions.

Microsoft analysts identified the extension’s primary motive as intercepting search traffic and collecting data. They warned that such data could be misused for user profiling, targeted advertising, or other privacy violations, depending on the attackers’ intent.

Advanced Techniques and Concealed Operations

Following responsible disclosure, Google removed the extension from the Chrome Web Store. Unlike traditional search hijackers, this extension leveraged modern browser technology, integrating its malicious activities within normal browsing behavior.

Moreover, the extension came equipped with server-side code, allowing it to record all incoming requests, including HTTP headers, user-agent strings, and IP addresses. This setup confirmed the operation’s intentional design for extensive data collection.

Preventive Measures and Recommendations

The fake extension declared itself as the default search provider, using a domain that closely resembled the legitimate perplexity[.]ai service. This change was nearly imperceptible, further aiding its deceptive operations.

Microsoft recommends organizations limit extension installations to approved lists and enforce strict browser policies. Users are advised to verify the authenticity of extensions and be cautious of AI-themed tools, which are increasingly used in social engineering scams.

Monitoring unauthorized changes to browser settings and tracking traffic to unfamiliar domains are crucial steps in mitigating such threats. Organizations should remain vigilant to prevent similar attacks in the future.

Indicators of Compromise (IoCs) include the typosquatted domain perplexity-ai[.]online and the extension ID flkebkiofojicogddingbdmcmkpbplcd, used for intercepting search queries and redirecting them.

Cyber Security News Tags:AI security, browser extension, Cybersecurity, data interception, fake extensions, Google Chrome, Microsoft, Privacy, search hijacking, tech news

Post navigation

Previous Post: AI Costs in Cybersecurity: A Rising Challenge
Next Post: Security Flaws in AirDrop and Quick Share Exposed

Related Posts

OpenAnt: AI Tool for Detecting Software Vulnerabilities OpenAnt: AI Tool for Detecting Software Vulnerabilities Cyber Security News
Microsoft Data Center Outage Affects Windows 11 Updates Microsoft Data Center Outage Affects Windows 11 Updates Cyber Security News
KarstoRAT Malware Threatens with Extensive Control Abilities KarstoRAT Malware Threatens with Extensive Control Abilities Cyber Security News
20+ Malicious Apps on Google Play Actively Attacking Users to Steal Login Credentials 20+ Malicious Apps on Google Play Actively Attacking Users to Steal Login Credentials Cyber Security News
Bitter APT Hackers Exploit WinRAR Zero-Day Via Weaponized Word Documents to Steal Sensitive Data Bitter APT Hackers Exploit WinRAR Zero-Day Via Weaponized Word Documents to Steal Sensitive Data Cyber Security News
LockBit Operators Using Stealthy DLL Sideloading Technique to Load Malicious App as Legitimate One LockBit Operators Using Stealthy DLL Sideloading Technique to Load Malicious App as Legitimate One Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Bash Vulnerabilities Threaten AI Coding Security
  • Cyber Threats Surrounding FIFA 2026: Key Insights
  • Bing Search Leads to Akira Ransomware Attack via SEO Poisoning
  • Chris Thompson’s Journey: From Game Hacker to Cybersecurity Pioneer
  • Severe SimpleHelp Flaw Used to Deploy New Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Bash Vulnerabilities Threaten AI Coding Security
  • Cyber Threats Surrounding FIFA 2026: Key Insights
  • Bing Search Leads to Akira Ransomware Attack via SEO Poisoning
  • Chris Thompson’s Journey: From Game Hacker to Cybersecurity Pioneer
  • Severe SimpleHelp Flaw Used to Deploy New Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark