Close Menu
Web StatWeb Stat
  • Home
  • News
  • United Kingdom
  • Misinformation
  • Disinformation
  • AI Fake News
  • False News
  • Guides
Trending

Russia and Israel hit back at Sanchez over claims they fuelled Ceuta crisis

September 2, 2026

AusPost CEO’s false testimony understates impact of post office closures – News Hub

September 2, 2026

6 weeks after Blissfest injury, police warn against misinformation spreading

September 1, 2026
Facebook X (Twitter) Instagram
Web StatWeb Stat
  • Home
  • News
  • United Kingdom
  • Misinformation
  • Disinformation
  • AI Fake News
  • False News
  • Guides
Subscribe
Web StatWeb Stat
Home»AI Fake News
AI Fake News

Fake Perplexity AI Extension Captures Real-Time Search Suggestions and Browser Signals

News RoomBy News RoomJune 30, 2026Updated:July 1, 20264 Mins Read
Facebook Twitter Pinterest WhatsApp Telegram Email LinkedIn Tumblr

The digital landscape is currently witnessing a troubling new trend where the trusted names of popular AI tools are being weaponized against unsuspecting users. A recent discovery by Microsoft analysts has shed light on a sophisticated malicious browser extension, disguised as the well-known AI search engine Perplexity AI. This deceptive tool, titled “Search for perplexity ai,” was crafted with such precision that it mirrored the look and feel of a legitimate productivity application. By operating under a fake identity, the extension exploited the trust users naturally place in recognizable brands, making it incredibly difficult for the average person to spot that they were being compromised the moment they installed the software.

At the technical heart of this operation was a clever exploitation of Chromium-based browsers. Once installed, the extension didn’t just sit on the toolbar; it quietly seized control of the browser’s default search settings. The level of interference was both deep and silent: every search query a user typed—even those entered mid-thought before hitting the “Enter” key—was stealthily routed through an attacker-controlled server before being forwarded to a legitimate search engine like Google or Bing. Because the final results appeared on a familiar search page, the victim experienced a seamless, “normal” browsing experience, while in the background, their data was being harvested by malicious actors.

What sets this particular threat apart from the standard “search hijacker” malware of the past is how it utilized modern browser technology to remain completely invisible. Rather than triggering clunky, obvious redirects that would alert a user, the extension employed browser-native APIs to blend its malicious activity into the background of daily internet use. Furthermore, the extension was supported by a complex server-side infrastructure. Every piece of data—including HTTP headers, user IP addresses, and user-agent strings—was meticulously logged. This confirmed that the operation was not a haphazard glitch, but a deliberate, architecturally sound system designed for long-term data collection and user profiling.

The deception went even deeper through the use of a typosquatted domain, “perplexity-ai[.]online.” By configuring the browser to treat this fake domain as the default search provider, the attackers ensured that every character typed into the address bar was intercepted and logged on their private infrastructure. The inclusion of powerful network permissions allowed the extension to monitor, redirect, and inspect traffic at a granular level. To make matters worse, the criminals included a deceptive “onboarding” page, which mimicked a professional product setup flow. This psychological tactic is designed to build a false sense of security, convincing the user that they are setting up a helpful new AI tool while the software is actually settling into their browser to begin its surveillance.

The threat’s modular design also reveals a concerning level of foresight by its creators. While only the Perplexity-specific ruleset was active at the time of discovery, researchers noted that the extension contained dormant rulesets for Google and Bing. This suggests that the attackers could have scaled their campaign of mass surveillance across virtually any platform with minimal effort. While Google has since removed the extension from the Chrome Web Store following responsible disclosure, the incident serves as a stark reminder of how vulnerable our browser environments are to these types of “AI-themed” social engineering campaigns.

In an era where AI tools are the latest hot commodity, users must be more vigilant than ever regarding what software they grant clearance to their browsers. To stay safe, it is crucial to verify the publisher and the specific URL of any extension before hitting ‘install,’ and to remain suspicious of tools that promise to “integrate” AI into your search bar. Organizations, meanwhile, should look into enforcing strict browser policies that limit installations to an approved whitelist and actively monitor for unusual outbound traffic. By replacing blind trust with a proactive security mindset, we can effectively mitigate the risk posed by these increasingly sophisticated digital shadows.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
News Room
  • Website

Keep Reading

Trump’s AI fakery in Iran war may prove the ultimate betrayal of Americans’ trust, experts warn

Senate impeachment court calls out fake, ‘AI’ photos of witness Ortonio wearing earpiece

Right-wing candidate used fake AI portraits in council campaign

Shalini Pandey condemns fake AI-generated video circulating online

Trump’s fake AI video of Kharg Island ‘attack’ leaves US military scrambling to explain

Instagram cracks down on AI accounts pretending to be human

Editors Picks

AusPost CEO’s false testimony understates impact of post office closures – News Hub

September 2, 2026

6 weeks after Blissfest injury, police warn against misinformation spreading

September 1, 2026

Spanish prime minister points finger at Israel, Russia disinformation over Ceuta migrant crisis

September 1, 2026

Police warn against misinformation spreading after injury at Northern Michigan festival – 9and10News.com

September 1, 2026

‘Polish Annexation’ Hoax Campaign Spotlights Czech Disinformation Vulnerability

September 1, 2026

Latest Articles

SEC Charges 38 Entities Over False Investment Adviser Filings — TradingView News

September 1, 2026

The media ‘misinformation’ about a molesting “Irish” doctor

September 1, 2026

Russia calls Germany’s Leipzig drone attack claims false and an unprecedented escalation

September 1, 2026

Subscribe to News

Get the latest news and updates directly to your inbox.

Facebook X (Twitter) Pinterest TikTok Instagram
Copyright © 2026 Web Stat. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Contact

Type above and press Enter to search. Press Esc to cancel.