The Containment Era is here. →Explore

Executive Summary

In June 2026, Microsoft identified a malicious Chrome extension named "Search for perplexity ai" that impersonated the AI search engine Perplexity. This extension intercepted users' search queries and address bar inputs, routing them through an attacker-controlled server before redirecting to legitimate search results. The extension set itself as the default search engine upon installation, capturing every character typed into the address bar and transmitting this data, along with browser headers, IP addresses, and user agents, to the attacker's server. Microsoft reported the extension to Google, leading to its removal from the Chrome Web Store. (thehackernews.com)

This incident underscores a growing trend of malicious browser extensions exploiting the popularity of AI tools to harvest sensitive user data. Similar campaigns have targeted users by masquerading as AI assistants, leading to significant data breaches. Organizations must remain vigilant, implementing strict policies on browser extensions and educating users about the risks associated with unverified add-ons. (techradar.com)

Why This Matters Now

The rise of AI-themed malicious extensions highlights the urgent need for enhanced browser security measures and user awareness to prevent data breaches and protect sensitive information.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Users should immediately remove the extension, reset their default search engine settings, and monitor their accounts for any unusual activity.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to intercept and exfiltrate sensitive user data by enforcing strict segmentation and controlled egress policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to distribute and execute malicious code within the cloud environment would likely be constrained, reducing the risk of initial compromise.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges within the cloud environment would likely be constrained, limiting unauthorized access.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's ability to move laterally within the cloud environment would likely be constrained, reducing the risk of further compromise.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to establish command and control channels would likely be constrained, reducing the risk of data exfiltration.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's ability to exfiltrate data from the cloud environment would likely be constrained, reducing the risk of data loss.

Impact (Mitigations)

The attacker's ability to collect and exploit sensitive user information would likely be constrained, reducing the risk of privacy violations.

Impact at a Glance

Affected Business Functions

  • Search Engine Operations
  • User Data Privacy
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

User search queries and address bar inputs were intercepted and logged by the malicious extension.

Recommended Actions

  • Implement strict browser extension policies to allow only approved extensions.
  • Regularly audit browser settings and extensions for unauthorized changes.
  • Educate users on the risks of installing unverified extensions, especially those mimicking popular services.
  • Deploy network monitoring to detect and block communications with known malicious domains.
  • Utilize endpoint security solutions capable of detecting and preventing unauthorized data exfiltration.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image