Fake AI, Real Spies: 260,000 Users Hit by Malicious Browser Extensions
ID: 187d3930-5014-57e5-b2a1-f956895398d5
STIX ID: report--187d3930-5014-57e5-b2a1-f956895398d5
Feed Name: securityonline.info
Threat Score
LayerX research uncovered a coordinated campaign of over 30 malicious browser extensions impersonating popular AI tools (ChatGPT, Claude, Gemini, Grok) that together impacted ~260,000 users. The extensions render remote iframes (notably tapnetic.pro) to act as privileged proxies, enabling remote-controlled behavior, silent capability changes, and data exfiltration (page content, Gmail DOM scraping, voice telemetry); operators use extension-spraying to evade takedowns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
