Chromium extension uses AI‑related branding to redirect browser search
2026-06-30T08:52:23Z•26cf00ab4b093f5d068135a28e85f5a99587de37c0c0bb087e9e74bcedfd39db
AI browsing agentAmadeyAutoJackMV3 APIMastraPerplexity spoofSapphire SleetStealCai brandingbrowser extension abusechromium extensionfake LNK/shortcuthospitality sectorinfostealerlocalhost abusenode.js implantnpm compromisepersistencephoto ZIP campaignpostinstall payloadremote code executionsearch redirectionsupply chainsupply-chain attacktake down
What happened
This Microsoft Security Blog feed contains multiple June 2026 threat reports and research updates. Key items: a malicious Chromium extension spoofing AI-branded services (Perplexity AI) that uses MV3 extension APIs and intermediary infrastructure to redirect browser search traffic; a multi-stage “photo ZIP” campaign targeting hospitality organizations in Europe and Asia that uses fake image shortcut files to drop a persistent Node.js implant; a technical breakdown and takedown of the StealC and Amadey infostealer ecosystems by Microsoft’s DCU; AutoJack research demonstrating how a maliciousweb
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 26cf00ab4b093f5d068135a28e85f5a99587de37c0c0bb087e9e74bcedfd39db
- Enrichment time
- 2026-06-30T08:52:23Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.