Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious AI Extension Hijacks Search Data

Malicious AI Extension Hijacks Search Data

Posted on June 30, 2026 By CWS

A deceptive browser extension, masquerading as the widely recognized AI tool Perplexity AI, has been discovered hijacking user search data and browser signals. This incident highlights the vulnerability of trusted brand names being exploited to compromise user privacy.

The extension, titled “Search for perplexity ai,” mimicked a legitimate AI tool to evade detection by users. It specifically targeted browsers built on the Chromium framework, modifying the default search settings immediately upon installation.

How the Malicious Extension Operated

Once installed, the extension rerouted user searches through its own servers before reaching search engines like Google or Bing. This seamless operation ensured that users remained unaware of the data interception occurring during their browsing sessions.

Microsoft analysts identified the extension’s primary motive as intercepting search traffic and collecting data. They warned that such data could be misused for user profiling, targeted advertising, or other privacy violations, depending on the attackers’ intent.

Advanced Techniques and Concealed Operations

Following responsible disclosure, Google removed the extension from the Chrome Web Store. Unlike traditional search hijackers, this extension leveraged modern browser technology, integrating its malicious activities within normal browsing behavior.

Moreover, the extension came equipped with server-side code, allowing it to record all incoming requests, including HTTP headers, user-agent strings, and IP addresses. This setup confirmed the operation’s intentional design for extensive data collection.

Preventive Measures and Recommendations

The fake extension declared itself as the default search provider, using a domain that closely resembled the legitimate perplexity[.]ai service. This change was nearly imperceptible, further aiding its deceptive operations.

Microsoft recommends organizations limit extension installations to approved lists and enforce strict browser policies. Users are advised to verify the authenticity of extensions and be cautious of AI-themed tools, which are increasingly used in social engineering scams.

Monitoring unauthorized changes to browser settings and tracking traffic to unfamiliar domains are crucial steps in mitigating such threats. Organizations should remain vigilant to prevent similar attacks in the future.

Indicators of Compromise (IoCs) include the typosquatted domain perplexity-ai[.]online and the extension ID flkebkiofojicogddingbdmcmkpbplcd, used for intercepting search queries and redirecting them.

Cyber Security News Tags:AI security, browser extension, Cybersecurity, data interception, fake extensions, Google Chrome, Microsoft, Privacy, search hijacking, tech news

Post navigation

Previous Post: AI Costs in Cybersecurity: A Rising Challenge
Next Post: Security Flaws in AirDrop and Quick Share Exposed

Related Posts

APT36 Hackers Attacking Indian Government Entities to Steal Login Credentials APT36 Hackers Attacking Indian Government Entities to Steal Login Credentials Cyber Security News
APT Hackers Exploit ChatGPT to Create Sophisticated Malware and Phishing Emails APT Hackers Exploit ChatGPT to Create Sophisticated Malware and Phishing Emails Cyber Security News
Critical 0-Day RCE Vulnerability in Networking Devices Exposes 70,000+ Hosts Critical 0-Day RCE Vulnerability in Networking Devices Exposes 70,000+ Hosts Cyber Security News
SnappyClient Malware Threatens Windows with Stealthy Data Breaches SnappyClient Malware Threatens Windows with Stealthy Data Breaches Cyber Security News
ChatGPT Hacked Using Custom GPTs Exploiting SSRF Vulnerability to Expose Secrets ChatGPT Hacked Using Custom GPTs Exploiting SSRF Vulnerability to Expose Secrets Cyber Security News
Windows Imaging Component Vulnerability Can Lead to RCE Attacks Under Complex Attack Scenarios Windows Imaging Component Vulnerability Can Lead to RCE Attacks Under Complex Attack Scenarios Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Crypter Services Bypass Windows Security Tools
  • DCRat Malware Concealed in SVG via HTML Smuggling
  • Google Cloud’s Quantum Cryptography Plan Targets 2029
  • Dysphoria Botnet Exploits IoT Devices for Cyber Attacks
  • Cybersecurity Updates: Rapid7 Layoffs and Boeing 737 Hack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Crypter Services Bypass Windows Security Tools
  • DCRat Malware Concealed in SVG via HTML Smuggling
  • Google Cloud’s Quantum Cryptography Plan Targets 2029
  • Dysphoria Botnet Exploits IoT Devices for Cyber Attacks
  • Cybersecurity Updates: Rapid7 Layoffs and Boeing 737 Hack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark