Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious AI Extension Hijacks Search Data

Malicious AI Extension Hijacks Search Data

Posted on June 30, 2026 By CWS

A deceptive browser extension, masquerading as the widely recognized AI tool Perplexity AI, has been discovered hijacking user search data and browser signals. This incident highlights the vulnerability of trusted brand names being exploited to compromise user privacy.

The extension, titled “Search for perplexity ai,” mimicked a legitimate AI tool to evade detection by users. It specifically targeted browsers built on the Chromium framework, modifying the default search settings immediately upon installation.

How the Malicious Extension Operated

Once installed, the extension rerouted user searches through its own servers before reaching search engines like Google or Bing. This seamless operation ensured that users remained unaware of the data interception occurring during their browsing sessions.

Microsoft analysts identified the extension’s primary motive as intercepting search traffic and collecting data. They warned that such data could be misused for user profiling, targeted advertising, or other privacy violations, depending on the attackers’ intent.

Advanced Techniques and Concealed Operations

Following responsible disclosure, Google removed the extension from the Chrome Web Store. Unlike traditional search hijackers, this extension leveraged modern browser technology, integrating its malicious activities within normal browsing behavior.

Moreover, the extension came equipped with server-side code, allowing it to record all incoming requests, including HTTP headers, user-agent strings, and IP addresses. This setup confirmed the operation’s intentional design for extensive data collection.

Preventive Measures and Recommendations

The fake extension declared itself as the default search provider, using a domain that closely resembled the legitimate perplexity[.]ai service. This change was nearly imperceptible, further aiding its deceptive operations.

Microsoft recommends organizations limit extension installations to approved lists and enforce strict browser policies. Users are advised to verify the authenticity of extensions and be cautious of AI-themed tools, which are increasingly used in social engineering scams.

Monitoring unauthorized changes to browser settings and tracking traffic to unfamiliar domains are crucial steps in mitigating such threats. Organizations should remain vigilant to prevent similar attacks in the future.

Indicators of Compromise (IoCs) include the typosquatted domain perplexity-ai[.]online and the extension ID flkebkiofojicogddingbdmcmkpbplcd, used for intercepting search queries and redirecting them.

Cyber Security News Tags:AI security, browser extension, Cybersecurity, data interception, fake extensions, Google Chrome, Microsoft, Privacy, search hijacking, tech news

Post navigation

Previous Post: AI Costs in Cybersecurity: A Rising Challenge
Next Post: Security Flaws in AirDrop and Quick Share Exposed

Related Posts

Cloudflare Fixes Critical Pingora Vulnerabilities Cloudflare Fixes Critical Pingora Vulnerabilities Cyber Security News
Interlock Ransomware Employs ClickFix Technique to Run Malicious Commands on Windows Machines Interlock Ransomware Employs ClickFix Technique to Run Malicious Commands on Windows Machines Cyber Security News
Let’s Encrypt Started to Issue SSL/TLS Certificate for IP Address Let’s Encrypt Started to Issue SSL/TLS Certificate for IP Address Cyber Security News
Malicious Code in mistralai PyPI Package Endangers Users Malicious Code in mistralai PyPI Package Endangers Users Cyber Security News
New Albiriox Malware Attacking Android Users to Take Complete Control of their Device New Albiriox Malware Attacking Android Users to Take Complete Control of their Device Cyber Security News
Hackers Utilize DKIM Replay to Exploit Trusted Invoices Hackers Utilize DKIM Replay to Exploit Trusted Invoices Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Chris Thompson’s Journey: From Game Hacker to Cybersecurity Pioneer
  • Severe SimpleHelp Flaw Used to Deploy New Malware
  • GitHub’s Advisory Database Faces Surge in Vulnerability Reports
  • Nissan Employee Data Exposed in Oracle PeopleSoft Attack
  • Security Flaws in AirDrop and Quick Share Exposed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Chris Thompson’s Journey: From Game Hacker to Cybersecurity Pioneer
  • Severe SimpleHelp Flaw Used to Deploy New Malware
  • GitHub’s Advisory Database Faces Surge in Vulnerability Reports
  • Nissan Employee Data Exposed in Oracle PeopleSoft Attack
  • Security Flaws in AirDrop and Quick Share Exposed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark