● 0 online
ANALYZING THREAT INTELLIGENCE
CTI
PORTAL
Threat Intelligence
INTELLIGENCE
Dashboard
IOC Search
Bulk Search
Pulses
Actors
Tags
Watchlist
ANALYSIS
Phishing
Knowledge Base
SYSTEM
Cache
← Back to Pulse Feed
PULSE
DETAIL
PULSE NAME
That AI Extension Helping You Write Emails? It's Reading Them First
WHITE
Tr1sa111
2026-05-05
Modified: 2026-05-05
21
IOCs
MEDIUM VOLUME
↓ CSV
↓ JSON
★ Watch
huiyi
browser extension
genai
remote access trojan
search hijacker
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
T1557
T1056.001
T1059.007
T1539
T1036.005
T1547.014
T1204.002
T1176
T1555
T1567
T1185
T1090
T1041
T1566
T1562.001
T1027
T1573
T1132
T1189
T1071.001
MALWARE FAMILIES
Chrome MCP Server
Supersonic AI
Reverse Recruiting
Chat AI for Chrome
AI Photo and Video Editor
Huiyi
Indicators of Compromise (21)
All
CVE
FileHash-SHA256
URL
domain
hostname
⎘ Copy All
TYPE
INDICATOR
DESCRIPTION
CREATED
CVE
CVE-2025-55182
—
2026-05-05
⎘
FileHash-SHA256
0cbf101e96f6d5c4146812f07105f8b89bd76dd994f540470cd1c4bc37df37d5
—
2026-05-05
⎘
FileHash-SHA256
4e38bee33237a8c8b17a2504013e506ca7cbf667a7f68a2d94d75db505c2149f
—
2026-05-05
⎘
FileHash-SHA256
604c7aef72892b56ac23ad54744376574239c8f0651e95dd5b6cf540eb70f7c3
—
2026-05-05
⎘
FileHash-SHA256
ac0a312398b3bf6b3d7c5169687ca72f361838bc5a90f2c0dbce2dc8e2094a02
—
2026-05-05
⎘
FileHash-SHA256
c9754454efede2dec2fcb856faa40424b8df378706b664a5ae4847fcd0336b53
—
2026-05-05
⎘
FileHash-SHA256
dfe307d957724ebe32331f92d53e366b7fa85968a9564c2285c5a0142ac9e1bb
—
2026-05-05
⎘
URL
http://api.reverserecruiting.io/
—
2026-05-05
⎘
URL
http://api.reverserecruiting.io/v1/profile/sync
—
2026-05-05
⎘
URL
http://banana.summarizer.one/quota
—
2026-05-05
⎘
URL
http://newextensioninstallweb.com/2025
—
2026-05-05
⎘
domain
chatgptforchrome.com
—
2026-05-05
⎘
domain
gosupersonic.email
—
2026-05-05
⎘
domain
newextensioninstallweb.com
—
2026-05-05
⎘
domain
notionapp.cn
—
2026-05-05
⎘
domain
pic-editor-chromeextension.uno
—
2026-05-05
⎘
domain
vomet.ru
—
2026-05-05
⎘
domain
xuix.top
—
2026-05-05
⎘
hostname
api.reverserecruiting.io
—
2026-05-05
⎘
hostname
banana.summarizer.one
—
2026-05-05
⎘
hostname
mcp-browser.qubecare.ai
—
2026-05-05
⎘
References (1)
↗ https://unit42.paloaltonetworks.com/high-risk-gen-ai-browser-extensions/