216.73.217.22

The AI Frame Campaign Continues

· Published 24/04/2026 05:05 · Modified 27/04/2026 14:38

Export JSON

Essential information

Published
24/04/2026 05:05
Modified
27/04/2026 14:38
Tags
2026-04-24 aiframe campaign browser security chrome extension credential-theft fraudulent paywall iframe injection two-factor authentication
Related entities
1 observables, 20 techniques (mitre), 29 others

Description

A malicious impersonating Google's Authenticator application has been identified as part of an ongoing campaign active since early 2026. The extension requests excessive permissions and contains dormant infrastructure suggesting a staged deployment model where malicious updates can be delivered without requiring further user approval. This extension is linked to at least six others through a shared developer front, with two already carrying fully operational malicious payloads. These extensions utilize hidden iframes to inject attacker-controlled content, deploy fraudulent paywalls for free services, and maintain bidirectional communication with command and control servers. The infrastructure maps directly to the , which has reportedly compromised over 260,000 users from 2025 to present, marking a continued evolution of this threat.

External references