A fake Perplexity extension had 4.7 stars and 10,000 users
Four of Sophos's customers installed the same browser extension. It carried Perplexity's name, it came from the official Chrome Web Store rather than some random download page, and it showed a 4.7-star rating from 67 reviews with a 10,000-user install count. What it actually did was hijack their searches, reroute them through a lookalike domain, and ship their browsing data to the people who built it, in real time.
That case sits inside a report Sophos X-Ops published this week, drawn from 12 months of its own incident response work between 2 July 2025 and 29 June 2026. Of 86 cases flagged as AI-related, 34 turned out to be genuinely malicious, and with four more from separate investigations the report covers 38 incidents. Software impersonation accounted for 30 of them. The most borrowed name, by a wide margin, was Claude, in 26 cases, ahead of ChatGPT, Copilot and Perplexity.
The other technique in the report is worth learning to recognise by sight. Sophos calls it InstallFix, a relative of the ClickFix trick: you land on a typosquatted site, usually through an ad, and it shows you a clean, professional-looking installation guide that asks you to paste a command somewhere. One case used a single mshta line that pulled its payload from a lookalike domain and then tried to hide itself inside a browser process. Nothing had to break in. The person at the keyboard did the installing.
So, two habits. Get AI software only from the vendor's own domain, typed in by hand rather than clicked from a search result, and treat any install guide that wants you to paste a command with the same flat suspicion you would give a phone call claiming to be your bank. Star ratings and review counts are decoration, and both are cheap to buy. Tendvane's Safety check lists your browser extensions next to your installed programs, which for most people is the only time that list ever gets looked at.