惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

L
LangChain Blog
阮一峰的网络日志
阮一峰的网络日志
WordPress大学
WordPress大学
博客园 - 司徒正美
罗磊的独立博客
D
Docker
Last Week in AI
Last Week in AI
爱范儿
爱范儿
M
MIT News - Artificial intelligence
V
V2EX
Google DeepMind News
Google DeepMind News
小众软件
小众软件
Apple Machine Learning Research
Apple Machine Learning Research
Microsoft Security Blog
Microsoft Security Blog
T
Tailwind CSS Blog
MyScale Blog
MyScale Blog
V
Visual Studio Blog
博客园 - 叶小钗
B
Blog RSS Feed
A
About on SuperTechFans
F
Fortinet All Blogs
T
The Blog of Author Tim Ferriss
Martin Fowler
Martin Fowler
P
Proofpoint News Feed

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! Hackers Use Rokarolla Android Malware to Disable Google Play Protect and Control Devices UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data
SearchJack Campaign Uses 23 Chrome Extensions to Hijack S...
Tushar Subhra Dutta · 2026-06-15 · via Cyber Security News

A coordinated campaign of 23 deceptive Chrome browser extensions has been quietly stealing users’ search queries and routing them through hidden revenue systems.

The operation, now dubbed SearchJack, has affected roughly 758,000 Chrome users worldwide without any of them realizing their searches were being hijacked.

Each extension presents itself as a useful tool, from satellite maps to productivity apps, while silently running a different operation in the background.

The way these extensions work is straightforward but difficult to detect. Once installed, they override the browser’s default search engine using a built-in Chrome feature called chrome_settings_overrides.

When a user types a query, it passes through operator-controlled relay servers before landing on a results page. The user sees what looks like a normal search, but every query has already passed through a monetization layer they never agreed to.

Researchers at MalExt Sentry identified the campaign using their automated scanning system, which monitors Chrome extension listings for suspicious activity.

According to MalExt Sentry’s report shared with Cyber Security News (CSN), MalExt Sentry said the scanner specifically flagged extensions abusing the chrome_settings_overrides manifest key to take over search settings.

The team traced at least eight distinct affiliate brokers, each identified by a unique tracking parameter in the final Yahoo redirect URL.

What makes SearchJack hard to spot is the gap between what extensions claim and what they actually do. One extension, Nautilus Search, tells users in its store listing that it never tracks searches or collects personal data.

Yet the linked privacy policy explicitly discloses collection of IP addresses, search queries, and device identifiers.

That is not an oversight. It is a direct false claim, potentially actionable under both GDPR and FTC frameworks. The scale of this campaign raises concerns beyond misleading store descriptions.

Since the operators control where search traffic flows, they can quietly switch from delivering normal results to serving phishing pages or malicious downloads without ever pushing an update to the extension.

That ability to escalate harm without touching the code is what elevates SearchJack from adware to a genuine security risk.

SearchJack Campaign Uses 23 Chrome Extensions

The technical backbone of SearchJack is built on a layered redirect system designed to stay completely invisible.

Most extensions are what researchers call shell extensions, containing almost nothing beyond the manifest file that sets the new default search engine.

There is no background script, no permission request, and no visible signal that anything unusual is happening. The same structural template appears across multiple extensions, with only the domain and icon swapped out.

A smaller group adds fake functionality, such as a basic maps viewer or video library, to pass store review and make the install feel legitimate.

These features are barely functional but enough to avoid automated removal. One extension, Search Toggler, shows users an interface that appears to let them switch between search engines.

In practice, all queries still pass through the operator’s server regardless of selection, and the actual routing logic is only injected at runtime, making it invisible to standard analysis tools.

The Broker Network Enabling the Campaign

Behind every extension sits a broker holding a revenue-sharing agreement with Yahoo’s search affiliate program, collecting a cut each time a user searches. The campaign spans eight such brokers, with the largest block tied to an unidentified operator.

Some brokers, like Becovi Ltd based in Dublin, are at least partially traceable. Others have no verifiable identity, making accountability nearly impossible.

One unusual case involves Fusebase Search, published under a legitimate company name, showing 609 reviews against only 490 current installs.

That ratio is mathematically impossible under normal conditions and points to either review manipulation or a prior policy violation that reset the install count.

Researchers recommend enforcement action at the broker level rather than targeting individual extensions, since extensions are disposable but affiliate accounts are not.

Users should audit their installed extensions, remove anything unfamiliar, and manually reset their default search engine in Chrome settings.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
Domainmyperfecttab[.]comPerfecTab Search redirect domain
Domainquery.quicksearchtool[.]comQuick Search Tool redirect domain
Domainsearch.getbettersearch-api[.]comBetter Search redirect domain
Domainnewtab[.]clubNewTab.Search redirect domain
Domainnautilus-notes[.]comNautilus Search redirect domain
Domainearthapp[.]netEarth extension redirect domain (infospace broker)
Domainwanderlustar[.]comWanderlustar redirect domain
Domainservices.templatesearchsvc[.]orgTemplate Search redirect domain
Domainearth3d[.]netEarth 3D redirect domain (infospace broker)
Domainmyfocalfind[.]comMy Focal Find redirect domain
Domaingreatstartapp[.]comGreat Start redirect domain (becovi broker)
Domainfreshfruittab[.]comFresh Fruit Search redirect domain
Domainviewmenuprices[.]comView Menu with Prices redirect domain (infospace broker)
Domainsearchtoggler[.]comSearch Toggler operator domain
Domainloginonlineapp[.]comEasy Login redirect domain (infospace broker)
Domainseek.searchthatweb[.]comSearchThatWeb redirect domain
Domainsearch.freshysearchapi[.]netFreshy Search redirect domain (trp broker)
Domainmyvideolibrary[.]infoVideo Search Extension redirect domain
Domainbestfreemaps[.]comGet Maps & Driving Directions + Satelliten Earth redirect domain
Domainsearchanything[.]coSearch Anything redirect domain (mnet broker)
Domainoasrchrdr[.]comSurfer Search redirect domain (fc broker)
Domains.fusebasesearch[.]comFusebase Search redirect domain (dcola broker)
Domainworthathousandwords[.]comSearch Toggler contact email domain
Extension IDhohedjmdoemgcpgdapepfhnilbedldnmPerfecTab Search (Chrome Extension ID)
Extension IDkeadechokmcohlcampccppbjjeabghcdQuick Search Tool (Chrome Extension ID)
Extension IDepdmngmgidehpmhjamdjcaecpligmcfhBetter Search (Chrome Extension ID)
Extension IDpookachmhghnpgjhebhilcidgdphdlhiNewTab.Search (Chrome Extension ID)
Extension IDflcaigefphghbcgbmfngbfdgipdflfpnNautilus Search (Chrome Extension ID)
Extension IDhnfdneofpohlkoeljnmkdocokcdk jiaaEarth (Chrome Extension ID)
Extension IDbgliakflmjnofiolfmnbncdmgfnibgnjWanderlustar (Chrome Extension ID)
Extension IDcnkcgoiimpncbonlilkekbigfhchcbgbTemplate Search (Chrome Extension ID)
Extension IDkbobdmmjbaljcombpliahadgoafgohcdEarth 3D (Chrome Extension ID)
Extension IDeeejfmalgedffijdepcdmgemfnadjefeMy Focal Find (Chrome Extension ID)
Extension IDmccmkaicbneobeclkbloeoopcfeipmioGreat Start (Chrome Extension ID)
Extension IDjeookppofphgjnhjkifeejcmjbpiogkaFresh Fruit Search (Chrome Extension ID)
Extension IDijbmkpeacbkgpfkomjbionjgdhbmlpfpView Menu with Prices (Chrome Extension ID)
Extension IDhodgcolihbmeagfcfpdfpnapfflmpbkbSearch Toggler (Chrome Extension ID)
Extension IDcpmjnpalighpdecgankobogpcmbceaigEasy Login (Chrome Extension ID)
Extension IDakimdaijebpdfo jiohhimbebkdigkccjSearchThatWeb (Chrome Extension ID)
Extension IDoikgbpcmdphfkhplgkfngjilemlo lannFreshy Search (Chrome Extension ID)
Extension IDefakcomgmimcekdejnoafmmbgnpdhdfmVideo Search Extension (Chrome Extension ID)
Extension IDgmapdckphdmbafmmcfoahhgoogdjeellGet Maps & Driving Directions (Chrome Extension ID)
Extension IDodafhekandnacimkenmaagnoemnpaakkSearch Anything (Chrome Extension ID)
Extension IDjgoihmjphghpnjedflgemmhjdaogimadSatelliten Earth (Chrome Extension ID)
Extension IDdllhnjhfilgcjopkgdekmdmfilpfceigSurfer Search (Chrome Extension ID)
Extension IDododhdcefemfdbnidbeipjpjaehadjenFusebase Search (Chrome Extension ID)
URL Parameterhspart=trpBroker tracking parameter — unknown operator
URL Parameterhspart=infospaceBroker tracking parameter — System1
URL Parameterhspart=flowsurfBroker tracking parameter — unknown operator
URL Parameterhspart=adkBroker tracking parameter — unknown operator
URL Parameterhspart=becoviBroker tracking parameter — Becovi Ltd, Dublin
URL Parameterhspart=imageadvanBroker tracking parameter — unknown operator
URL Parameterhspart=mnetBroker tracking parameter — unknown operator
URL Parameterhspart=fcBroker tracking parameter — unknown operator
URL Parameterhspart=dcolaBroker tracking parameter — unknown operator
Emailedgarlife1980[@]gmail[.]comPublisher account for Earth 3D extension

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.