216.73.217.22

Fake AI Assistant Extensions Targeting 260,000 Chrome Users via injected iframes

· Published 16/02/2026 14:28 · Modified 17/02/2026 16:08

Export JSON

Essential information

Published
16/02/2026 14:28
Modified
17/02/2026 16:08
Tags
2026-02-16 ai assistants browser security chrome extensions data harvesting extension spraying iframes
Related entities
6 techniques (mitre), 5 others

Description

A coordinated campaign of posing as has been uncovered, affecting over 260,000 users. These extensions, while appearing legitimate, embed remote, server-controlled interfaces inside extension-controlled surfaces, granting access to sensitive browser capabilities. The campaign consists of 30 different extensions sharing the same codebase, permissions, and backend infrastructure. Key features include remote iframe as the core UI, page content extraction, voice recognition capability, and Gmail integration. The extensions communicate with infrastructure under the tapnetic.pro domain, using subdomain segmentation for logical separation. The campaign employs tactics to evade takedowns and quickly restore distribution. This approach breaks the model, potentially allowing and user behavior monitoring.

External references