Executive Summary
In June 2026, a malicious Chromium-based browser extension impersonating the AI-powered search engine Perplexity AI was discovered. This extension intercepted user search queries and real-time suggestions, routing them through attacker-controlled infrastructure before redirecting to legitimate search providers. The primary objective appeared to be data collection for potential misuse, such as profiling or targeted advertising. Microsoft Threat Intelligence reported the extension to Google, leading to its removal from the Chrome Web Store.
This incident underscores the evolving tactics of threat actors leveraging AI-related branding to enhance the credibility of their malicious tools. The use of legitimate APIs and advanced permissions highlights the need for heightened vigilance and robust security measures to protect against sophisticated browser-based threats.
Why This Matters Now
The exploitation of AI branding in malicious browser extensions signifies a growing trend in cyber threats, emphasizing the urgency for organizations to implement stringent security protocols and user education to mitigate such risks.
Attack Path Analysis
The attacker tricked users into installing a malicious Chromium extension by spoofing the Perplexity AI brand, leading to the interception of search queries and real-time keystrokes. The extension exploited browser permissions to maintain persistence and evade detection, while routing intercepted data through attacker-controlled infrastructure. This enabled the exfiltration of sensitive user information, potentially facilitating further malicious activities.
Kill Chain Progression
Initial Compromise
Description
Users were deceived into installing a malicious Chromium extension that impersonated the Perplexity AI brand.
MITRE ATT&CK® Techniques
Browser Extensions
Browser Session Hijacking
Web Protocols
Malicious File
Spearphishing Link
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Applications and Workloads
Control ID: Pillar 3
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Browser hijacker extensions targeting search traffic pose significant data exfiltration risks, compromising customer queries and potentially violating PCI DSS compliance requirements.
Computer Software/Engineering
AI-branded malicious extensions exploit developer trust in productivity tools, creating supply chain risks through compromised search behavior and potential intellectual property exposure.
Health Care / Life Sciences
Search hijacking extensions can intercept sensitive medical queries and research terms, violating HIPAA encryption requirements and exposing patient information through unencrypted traffic.
Government Administration
Browser extensions with declarativeNetRequest permissions bypass traditional network controls, creating significant visibility gaps and potential NIST compliance violations in government environments.
Sources
- Chromium extension uses AI‑related branding to redirect browser searchhttps://www.microsoft.com/en-us/security/blog/2026/06/29/chromium-extension-uses-airelated-branding-redirect-browser-search/Verified
- Malicious Chromium extension spoofs Perplexity AI to hijack browser searcheshttps://www.csoonline.com/article/4191060/malicious-chromium-extension-spoofs-perplexity-ai-to-hijack-browser-searches.htmlVerified
- Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Inputhttps://thehackernews.com/2026/06/malicious-perplexity-chrome-extension.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF may not prevent the initial installation of malicious extensions, it could likely limit the extension's ability to communicate with unauthorized external servers.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could likely limit the extension's ability to access sensitive internal resources by enforcing strict access controls.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could likely limit the extension's ability to move laterally within the network by enforcing strict segmentation policies.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could likely detect and limit unauthorized outbound communications to attacker-controlled infrastructure.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could likely limit the exfiltration of sensitive data by enforcing strict outbound traffic policies.
While Aviatrix CNSF may not prevent the initial data exfiltration, it could likely limit the scope of data accessible to the attacker, thereby reducing the potential impact.
Impact at a Glance
Affected Business Functions
- User Search Privacy
- Data Security
- Brand Trust
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of user search queries and real-time keystrokes to attacker-controlled infrastructure.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict browser extensions' access to sensitive data and services.
- • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic from browser extensions.
- • Utilize Threat Detection & Anomaly Response to identify and respond to unusual extension behaviors.
- • Apply Multicloud Visibility & Control to gain insights into extension activities across different environments.
- • Educate users on the risks of installing unverified browser extensions and the importance of verifying sources.



