The instinctive reaction when you hear “malicious browser extension” is to picture some sketchy toolbar from a shady download site in 2009. That mental model is dangerously out of date. Unit 42’s latest research documents something far more sophisticated: AI-branded browser extensions that present themselves as legitimate productivity boosters while actively reading your emails, intercepting your prompts, and quietly exfiltrating credentials. This is a cybersecurity problem wearing a productivity costume, and the fact that it’s landing inside enterprise browsers at scale should be unsettling for anyone responsible for protecting a real environment.

AI browser extension security risk illustrated with abstract digital surveillance concept
AI-branded extensions are increasingly being used as data exfiltration tools disguised as productivity software. Source: Unit 42 / Palo Alto Networks

Pair this with the Q1 2026 email threat landscape Microsoft just documented, where CAPTCHA-gated phishing campaigns and QR code lures are driving credential theft at scale, and you start to see the shape of a problem that’s bigger than any single attack vector. The perimeter isn’t the edge of your network anymore. It’s the browser tab your finance team has open right now.

The Real Threat Model Behind AI Extensions

Here’s what makes the Unit 42 findings uncomfortable: these extensions aren’t exploiting some obscure browser vulnerability. They’re asking for permissions that users grant willingly, because the extension promises to summarize your inbox or rewrite your drafts. Read and change all your data on the websites you visit. That permission dialog sits between the attacker and your credentials, and most users click through it in about three seconds.

What Unit 42 actually found goes beyond passive data collection. Some of these extensions intercept AI prompts in real time, which means if your employees are feeding sensitive business context into a browser-based AI assistant, those queries can be captured and forwarded before the response ever renders. That’s not theoretical. That’s a live exfiltration channel sitting inside an ostensibly trusted tool, and it’s operating well above the layer where your traditional threat detection tools are looking.

Three Reasons This Bypasses Standard Defenses

  1. HTTPS encrypted traffic. Browser extensions operate inside the TLS session, so network-layer inspection sees encrypted blobs, not credential streams.
  2. Legitimate update mechanisms. Extensions can pull updated behavior from remote servers after installation, meaning a clean install can turn hostile days later.
  3. User-granted permissions. The extension has legitimate access to page content by design. There’s no brute-force attempt, no anomalous login, nothing for a traditional alert to fire on.

This is why defense in depth matters here in a concrete, not theoretical, way. Your firewall blocks unauthorized inbound connections. It does nothing about an extension reading DOM content and shipping it to a command-and-control endpoint over port 443. You need controls at the browser layer itself.

Phishing Infrastructure Got Smarter While You Were Watching the Inbox

Microsoft’s Q1 2026 email threat report is worth reading slowly, because the tactical evolution it documents is significant. CAPTCHA-gated phishing is now a standard evasion technique. The logic is straightforward: automated scanners don’t solve CAPTCHAs, so the malicious landing page is effectively invisible to many scanning systems until a real human resolves the challenge. Credential phishing campaigns are architecting around your security tooling deliberately.

QR code phishing has matured in the same direction. A QR code embedded in an email body is an image, not a URL. Link-scanning engines that check hyperlinks in real time see nothing suspicious. The user’s phone camera resolves the code, their mobile browser opens the phishing page, and that device is almost certainly outside your MDM policy and your threat protection stack entirely. It’s a clean bypass of email gateway controls that took years to tune.

Q1 2026 email threat landscape report showing phishing trends from Microsoft Security
Microsoft’s Q1 2026 data shows a material rise in CAPTCHA-gated and QR code phishing. Source: Microsoft Security Blog

Microsoft’s disruption of the Tycoon2FA phishing platform is the bright spot in that report. Taking down a phishing-as-a-service platform caused a measurable 15% drop in volume, which tells you how concentrated that infrastructure actually was. But it also tells you threat actors redistributed quickly. They always do. One platform’s disruption is not a solved problem.

When the Sender Is Legitimate and the Email Is Still a Scam

The PayPal situation Malwarebytes documented deserves specific attention because it breaks the one signal most users actually trust: sender reputation. Scammers are abusing PayPal’s own email delivery infrastructure to push tech support scams, which means the message arrives from a genuine PayPal address, passes SPF and DKIM validation, and lands in the inbox rather than spam. Every automated filter that relies on sender authentication sees a clean bill of health.

This is the logical endpoint of a years-long erosion in email trust signals. Threat actors have learned that the cheapest path to inbox delivery is abusing the legitimate infrastructure of a trusted brand rather than spoofing it outright. Spoofed domains trigger filters. Abuse of real infrastructure doesn’t. Your incident response playbook almost certainly includes “check sender domain” as an early triage step. That step now fails for an entire category of attacks.

The practical implication is that user training needs to explicitly cover this scenario. Showing employees what a PayPal phishing email looks like from a fake domain is no longer sufficient preparation. They need to understand that a legitimate PayPal sender address can still carry a scam payload, and the right behavior is to navigate to PayPal.com directly rather than interact with the email content at all.

What You Can Actually Do About This Right Now

Theory is cheap. Here’s where to spend actual time and effort across these interconnected threat surfaces.

On browser extensions, start with an audit you probably haven’t done recently. Pull the full list of installed extensions across your managed endpoints. You’re looking for extensions with broad host permissions, particularly those claiming AI functionality that were installed in the last six to twelve months. Any extension with access to all sites and no clear business justification should be treated as a candidate for removal pending review. This isn’t about being draconian; it’s about knowing what has privileged access to your browser sessions.

From there, move to enforcement. Modern enterprise browser management lets you maintain an allowlist of approved extensions and block installation of anything outside it. That’s the control you want. Alerting on new extension installations is useful but reactive. Blocking unapproved installations at policy is the security hardening move that actually reduces exposure.

For email threats, the QR code problem requires a specific answer. If your email gateway supports image-based URL extraction, that feature needs to be enabled and tested. Some platforms can now decode QR codes in email images and submit the resolved URL for threat inspection. If yours doesn’t support that, that’s a capability gap worth raising with your vendor. Manual user awareness is a partial compensating control, but it’s not a reliable one at scale.

CAPTCHA-gated phishing is harder to defeat technically, which means your investment here should go into post-click controls: browser isolation for high-risk users, MFA that’s resistant to real-time phishing relay (hardware keys or passkeys rather than TOTP), and credential monitoring to catch successful compromises quickly. The goal when you can’t prevent the click is to make the credential useless to the attacker even after they have it.

For the PayPal-style infrastructure abuse pattern, the control that matters most is reducing how much action users can take from email in the first place. If your internal guidance is “never call a number in an email, never click a payment link from email, always go directly to the site,” and that guidance is rehearsed rather than just written in a policy document, you’ve materially reduced the attack surface. That’s not a technical control, but it’s a real one.

Frequently Asked Questions

Can a firewall block malicious browser extension traffic?
A traditional perimeter firewall won’t stop a browser extension exfiltrating data, because that traffic rides inside HTTPS sessions initiated by the user’s own browser. You’d need TLS inspection at the proxy layer combined with browser-layer management controls to address this effectively. Perimeter tools and browser policy enforcement need to work together here.
How do QR code phishing attacks get past email security gateways?
Most email security tools scan hyperlinks in message bodies and headers. A QR code embedded as an image contains no hyperlink the scanner can parse directly. Some advanced gateways now include image-based QR decoding capabilities, but adoption is uneven. Until your gateway can decode and inspect QR-embedded URLs, this is a genuine detection gap that requires compensating controls at the endpoint and in user training.
If an email actually comes from PayPal’s servers, is there any technical way to flag it as suspicious?
Sender authentication checks like SPF, DKIM, and DMARC won’t help here because the email is legitimately sent through PayPal’s infrastructure. Detection needs to shift to content analysis, behavioral signals like unusual call-to-action language, and phone numbers embedded in email bodies. Some security platforms flag messages containing phone numbers specifically because that’s a strong indicator of tech support scam patterns. User awareness remains the most reliable last line in this scenario.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.