Executive Summary
In June 2026, Microsoft identified a malicious Chrome extension named "Search for perplexity ai" that impersonated the AI search engine Perplexity. This extension intercepted users' search queries and address bar inputs, routing them through an attacker-controlled server before redirecting to legitimate search results. The extension set itself as the default search engine upon installation, capturing every character typed into the address bar and transmitting this data, along with browser headers, IP addresses, and user agents, to the attacker's server. Microsoft reported the extension to Google, leading to its removal from the Chrome Web Store. (thehackernews.com)
This incident underscores a growing trend of malicious browser extensions exploiting the popularity of AI tools to harvest sensitive user data. Similar campaigns have targeted users by masquerading as AI assistants, leading to significant data breaches. Organizations must remain vigilant, implementing strict policies on browser extensions and educating users about the risks associated with unverified add-ons. (techradar.com)
Why This Matters Now
The rise of AI-themed malicious extensions highlights the urgent need for enhanced browser security measures and user awareness to prevent data breaches and protect sensitive information.
Attack Path Analysis
The attacker distributed a malicious Chrome extension posing as 'Search for perplexity ai' to intercept user searches and address bar inputs. Upon installation, the extension set itself as the default search engine, routing all queries through an attacker-controlled server to log data before redirecting users to legitimate search results. The extension also captured every character typed into the address bar by modifying the browser's live search suggestions. This data exfiltration occurred without user consent, leading to unauthorized collection of sensitive information.
Kill Chain Progression
Initial Compromise
Description
Users installed a malicious Chrome extension named 'Search for perplexity ai' from the Chrome Web Store, believing it to be a legitimate tool.
MITRE ATT&CK® Techniques
Browser Extensions
Browser Session Hijacking
Web Protocols
Automated Collection
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for managing system and software vulnerabilities are defined, documented, in use, and known to all affected parties.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Device Security
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Malicious Chrome extension infostealer poses critical risk to financial data, client searches, and regulatory compliance under PCI/NIST frameworks requiring encrypted traffic protection.
Health Care / Life Sciences
Browser extension intercepting searches threatens patient data privacy, HIPAA compliance violations, and medical research confidentiality through unencrypted traffic monitoring capabilities.
Law Practice/Law Firms
Attorney-client privilege compromised through search interception and address bar logging, creating ethical violations and confidential case information exposure risks.
Computer Software/Engineering
Software development environments vulnerable to intellectual property theft through intercepted technical searches, API documentation queries, and proprietary development research activities.
Sources
- Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Inputhttps://thehackernews.com/2026/06/malicious-perplexity-chrome-extension.htmlVerified
- Fake Chrome AI extensions targeted over 300,000 users to steal emails, personal data and morehttps://www.techradar.com/pro/security/fake-chrome-ai-extensions-targeted-over-300-000-users-to-steal-emails-personal-data-and-moreVerified
- Malicious Chrome extensions can spy on your ChatGPT chatshttps://www.malwarebytes.com/blog/news/2026/01/malicious-chrome-extensions-can-spy-on-your-chatgpt-chatsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to intercept and exfiltrate sensitive user data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to distribute and execute malicious code within the cloud environment would likely be constrained, reducing the risk of initial compromise.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges within the cloud environment would likely be constrained, limiting unauthorized access.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the cloud environment would likely be constrained, reducing the risk of further compromise.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels would likely be constrained, reducing the risk of data exfiltration.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate data from the cloud environment would likely be constrained, reducing the risk of data loss.
The attacker's ability to collect and exploit sensitive user information would likely be constrained, reducing the risk of privacy violations.
Impact at a Glance
Affected Business Functions
- Search Engine Operations
- User Data Privacy
Estimated downtime: N/A
Estimated loss: N/A
User search queries and address bar inputs were intercepted and logged by the malicious extension.
Recommended Actions
Key Takeaways & Next Steps
- • Implement strict browser extension policies to allow only approved extensions.
- • Regularly audit browser settings and extensions for unauthorized changes.
- • Educate users on the risks of installing unverified extensions, especially those mimicking popular services.
- • Deploy network monitoring to detect and block communications with known malicious domains.
- • Utilize endpoint security solutions capable of detecting and preventing unauthorized data exfiltration.



