INTEL_REPORT
Microsoft Security Blog · published 6/29/2026, 4:27:46 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Chromium extension uses AI‑related branding to redirect browser search A malicious Chromium-based extension that spoofs the AI-powered answer engine Perplexity AI redirects browser search traffic using MV3 APIs and intermediary infrastructure. The post Chromium extension uses AI‑related branding to redirect browser search appeared first on Microsoft Security Blog . In this article Extension overview Key indicators of malicious behavior Dynamic analysis findings Mitigation a…
https://www.microsoft.com/en-us/security/blog/2026/06/29/chromium-extension-uses-airelated-branding-redirect-browser-search
sha256:4d8e59d441a09fb0da6dc963e7a1baeda34d8a90a0aa6cd2b89eb409e65c3b06
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| google-rules.json |
| Open → |
| domain | bing.com | Open → |
| domain | extension.tilda.ws | Open → |
| domain | suggestqueries.google.com | Open → |
| domain | nginx.conf | Open → |
| domain | oda.digital | Open → |
| url | https://perplexity-ai.online/search/ | Open → |
| url | https://perplexity-ai.online/favicon.ico | Open → |
| url | https://perplexity-ai.online/search?output=firefox&q= | Open → |
| url | https://extension.tilda.ws/perplexityai | Open → |