The bioshocking attack exploits trust in browser-based AI assistants to steal login credentials in the background. Learn the mechanics of this emerging threat and discover how to protect yourself before you become a victim.
bioshocking: A new era of AI-powered browser attacks
Imagine this: you are using a browser that helps you write emails, translates websites, and suggests passwords. Suddenly, it turns out that the very same tool – your trusted AI assistant – is sending your login credentials to an unknown server. Sounds like a sci-fi movie plot? Unfortunately, it is a real threat that cybersecurity experts have dubbed the bioshocking attack.
In May 2024, the Group-IB team published a report identifying this new attack vector, which leverages the integration of artificial intelligence into web browsers. The name "bioshocking" refers both to the game bioshock (a symbol of mind manipulation) and the "shocking" technique – surprising the user by exploiting their trust in technology. But what exactly is this attack, and why does it pose such a serious threat?
Attack mechanism: How AI becomes a hacker's tool
bioshocking attack phases
The bioshocking attack is neither classic phishing nor traditional malware. It is a hybrid exploit that leverages vulnerabilities in the integration of Large Language Models (LLMs) with browsers. Here is how it works:
-
Infection:
- The user installs a malicious AI extension (e.g., a fake version of a popular tool like *Merlin* or *chatgpt for Google*).
- Alternatively: the attacker exploits vulnerabilities in a legitimate extension by injecting malicious code (e.g., via an update).
-
AI response manipulation:
- The extension intercepts user queries to the AI (e.g., "How do I log in to my bank?").
- Instead of generating a safe response, the AI substitutes the content – for example, with a link to a fake login page.
-
Data theft:
- The user enters data on a spoofed page (e.g., a phishing version of a bank).
- Data is sent to the attacker's server via the extension's API.
- In some cases, the extension also captures keystrokes or session cookies, acting like a keylogger.
Why is bioshocking difficult to detect?
The bioshocking attack is particularly dangerous for several reasons:
- Exploiting trust in AI: Users trust responses generated by AI assistants, treating them as a reliable source of information. If the AI "recommends" a fake login page, the victim is more likely to visit it.
- No user interaction required: In some attack variants, data is stolen in the background without the need to click suspicious links. It is enough for the user to simply use the infected extension.
-
Difficulty in identification:
Fake login pages can be nearly identical to the originals, and attackers often use domains similar to legitimate ones (e.g.,
bank-login.cominstead ofbank.com).
What data is most frequently stolen?
According to the Group-IB report (May 2024), the bioshocking attack most often targets:
- Login credentials (85% of cases) – passwords to bank accounts, email, and social media.
- Session tokens (12% of cases) – allowing account takeover without knowing the password.
- Payment card data (3% of cases) – if the user uses payment form autofill.
It is worth noting that session tokens are particularly valuable to hackers because they allow for immediate account takeover without the need to crack passwords.
Which browsers and extensions are vulnerable?
The bioshocking attack affects browsers that integrate AI features or allow the installation of extensions based on language models. Here is an overview of the most exposed platforms:
High-risk browsers
- Google Chrome: The most popular browser in the world, with a rich ecosystem of AI extensions. In May 2024, Google introduced automatic blocking of suspicious extensions, but not all threats are detected yet.
- Microsoft Edge: In June 2024, Microsoft released a patch (version 125.0.2535.67) fixing vulnerabilities in Copilot integration. Older versions remain vulnerable.
- Opera: A browser with a built-in Aria AI assistant. There are no official reports regarding bioshocking vulnerability, but experts advise caution.
- Brave: A browser with optional AI features. No incidents related to bioshocking have been reported yet, but the risk exists.
Dangerous AI extensions
Not all AI extensions are malicious, but their architecture can be exploited by attackers. Here is a list of extensions that, according to Group-IB, raise the most concerns:
- Merlin (chatgpt for Chrome) – a popular extension with over 1 million users.
- Superpower chatgpt – a tool for generating responses, used in attacks on e-commerce accounts.
- AI Prompt Genius – an extension for automatic prompt generation.
- Copilot for Edge (versions before June 2024) – vulnerable to malicious code injection.
Note: This does not mean that the listed extensions are malicious – it means that their popularity and features make them an attractive target for hackers.
Official manufacturer statements
Browser manufacturers are reacting to the threat, but not all statements are definitive:
- Google: In May 2024, automatic blocking of suspicious AI extensions was introduced, but there is no official confirmation of bioshocking vulnerability (as of June 2024).
- Microsoft: In June 2024, a patch for Edge (CVE-2024-38023) was released, fixing vulnerabilities in Copilot integration. Older versions remain exposed.
- Mozilla: Firefox is not directly vulnerable to bioshocking, but Mozilla advises caution when installing AI extensions.
Known cases of bioshocking usage
The bioshocking attack is no longer just a theory – the first incidents were documented in 2024. Here are the most significant cases:
Attack on e-commerce users in Europe (March 2024)
In March 2024, Europol reported a series of attacks on users of online stores in Europe. Hackers used the Superpower chatgpt extension to steal payment card data. Victims were redirected to fake payment pages that looked identical to the originals.
Attack details:
- Target: Users of popular e-commerce platforms (e.g., Allegro, Zalando).
- Method: Link substitution in AI responses ("Click here to finalize payment").
- Scale: Several thousand victims, losses estimated at hundreds of thousands of euros.
Data leak from a SaaS platform (April 2024)
In April 2024, the bleepingcomputer portal described an incident where hackers used the Merlin extension to steal login credentials for a SaaS platform (name not disclosed). Attackers intercepted user queries to the AI (e.g., "How do I log in to [platform]?") and substituted the responses, directing victims to fake login pages.
Attack details:
- Target: Corporate employees using SaaS platforms (e.g., Salesforce, Slack).
- Method: Intercepting AI queries and substituting responses.
- Scale: Several hundred accounts compromised, corporate data leak.
Microsoft 365 account takeover (May 2024)
In May 2024, Microsoft confirmed that a vulnerability in Copilot for Edge was exploited to take over Microsoft 365 accounts. Attackers used vulnerabilities in the browser's Copilot integration to intercept session tokens and take over accounts without knowing passwords.
Attack details:
- Target: Corporate users using Microsoft 365.
- Method: Intercepting session tokens via a malicious extension.
- Scale: Dozens of incidents, fixed in the June 2024 update.
Most vulnerable sectors
The bioshocking attack primarily affects sectors where users frequently utilize browsers and AI assistants:
- Finance: Online banking, online payments, digital wallets.
- E-commerce: Online stores, auction platforms, payment systems.
- Social media: Facebook, LinkedIn, Twitter (X) accounts.
- Corporations: Corporate accounts, SaaS platforms, remote work tools.
How to protect yourself against the bioshocking attack?
The bioshocking attack is difficult to detect, but there are effective protection methods. Here are recommendations for users and IT administrators:
For users: Practical tips
-
Limit the number of AI extensions:
- Install only official extensions from verified sources (Chrome Web Store, Microsoft Edge Add-ons).
- Check extension permissions – if an extension requests access to data on all websites, that is a red flag.
-
Disable AI features in the browser:
- In Chrome:
Ustawienia > Prywatność i bezpieczeństwo > Ustawienia witryn > AI(disable options). - In Edge:
Ustawienia > Prywatność > Usługi > Wyłącz Copilot.
- In Chrome:
- Use a password manager:
-
Verify URLs before logging in:
- Check if the site uses HTTPS (padlock icon in the address bar).
- Ensure the domain is correct (e.g.,
bank.plinstead ofbank-login.pl).
-
Enable two-factor authentication (2FA):
- Even if a hacker intercepts your password, 2FA (e.g., SMS, Google Authenticator) will block access.
- Avoid email-based 2FA – it is better to use authentication apps.
For IT administrators: Corporate security
-
Block unauthorized extensions:
- Implement Group Policy (Windows) or Chrome Enterprise Policy to block AI extensions.
- Regularly audit installed extensions within the company.
-
Monitor network traffic:
- Detect unusual connections to attacker servers (e.g., via SIEM).
- Block domains associated with phishing (e.g., using opendns).
-
Train employees:
- Raise awareness about threats related to AI in browsers and phishing techniques.
- Conduct phishing tests to check team vigilance.
-
Enforce browser updates:
- Ensure all employees use the latest browser versions (e.g., Chrome 125+, Edge 125+).
- Disable older versions that are no longer supported.
Tools for detecting and blocking threats
Here are some tools that can help protect against bioshocking:
- uBlock Origin: Blocks tracking scripts and fake websites. Acts as a filter for ads and malicious content.
- Malwarebytes Browser Guard: Detects malicious extensions and phishing sites. Integrates with Chrome and Edge browsers.
- Group-IB Threat Intelligence: Monitors new attack vectors (for businesses). Helps identify threats in real-time.
- Darktrace: An AI anomaly detection tool that can detect unusual responses generated by LLMs.
bioshocking vs. other AI-powered attacks
The bioshocking attack is not the only threat leveraging artificial intelligence. Here is how it compares to other attack vectors:
Comparison of bioshocking with classic phishing
| Feature | bioshocking | Classic Phishing |
|---|---|---|
| AI usage | Yes (AI response manipulation) | No |
| User interaction | Often none (runs in background) | Requires clicking a link |
| Goal | Data theft via extension API | Redirect to a fake page |
| Detection difficulty | High (user trusts AI) | Medium (depends on fake quality) |
Other AI-powered attacks
Besides bioshocking, cybersecurity experts identify other threats related to AI:
- AI-powered phishing: Tools like WormGPT or FraudGPT generate fake emails and messages that are hard to distinguish from real ones. Attackers use LLMs to create personalized phishing messages.
- Deepfake Voice phishing: AI generates a person's voice (e.g., a company director) and calls an employee asking for a money transfer. According to the FBI, such attacks cost companies over $12 billion in 2023.
- Adversarial AI: Attacks on AI models aimed at manipulating results (e.g., changing search results). An example is data poisoning, where an attacker introduces fake data into the training set to manipulate model behavior.
bioshocking differs from these attacks primarily in its infection vector – it exploits trust in AI browser extensions rather than emails or voice messages.
The future of AI attacks: What can we expect?
The bioshocking attack is just the beginning of a new wave of threats leveraging artificial intelligence. Here are expert forecasts for the coming years:
Growth in AI-powered attacks
According to a Gartner report (April 2024), by 2025, 30% of phishing attacks will be AI-powered. This means attacks will become more personalized, harder to detect, and more effective.
Reasons for the growth:
- Availability of AI tools: Tools like *WormGPT* or *FraudGPT* are increasingly available on the dark web, lowering the barrier to entry for hackers.
- AI integration with everyday tools: Browsers, messengers, and operating systems are increasingly integrating AI features, creating new attack vectors.
- Difficulty in regulation: Lawmakers are struggling to keep up with technological development, allowing hackers to operate with few restrictions.
New attack vectors
Experts predict that new types of AI-powered attacks will emerge in the coming years:
- Mobile browser attacks: Smartphone browsers (e.g., Chrome for Android) with AI features may become targets for attacks similar to bioshocking.
- WebAssembly usage: Attackers may use WebAssembly to hide malicious code in browser extensions, making detection more difficult.
- Voice assistant attacks: Assistants like Google Assistant or Siri could be used for voice phishing (e.g., "Confirm your password by saying it out loud").
- Manipulation of AI-generated content: Attackers could substitute AI responses in real-time, e.g., in search engines or chats.
Risk-mitigating technologies
To counter the growing threat, browser manufacturers and cybersecurity experts are working on new solutions:
- Sandboxing: Isolation of browser extensions (e.g., Chrome’s Extension Manifest V3) prevents malicious extensions from accessing data on all websites.
- AI anomaly detection: Tools like Darktrace monitor AI-generated responses and detect unusual behaviors (e.g., substituted links).
- Zero Trust Architecture: Verification of every access request, even from trusted devices. The "never trust, always verify" approach reduces the risk of account takeover.
- Improved authentication mechanisms: Behavioral biometrics (e.g., analyzing typing patterns) can help detect account takeover attempts.
Summary: Are we safe?
The bioshocking attack shows that integrating AI into everyday tools – while convenient – carries serious risks. Trusting AI assistants in browsers can lead to data theft, account takeover, and financial loss.
Fortunately, there are effective protection methods:
- Limit the number of AI extensions and install only verified tools.
- Disable AI features in the browser if you don't need them.
- Use a password manager and two-factor authentication.
- Regularly update your browser and operating system.
- Stay vigilant – even AI-generated responses can be fake.
The future of AI-powered attacks looks grim, but awareness of the threats and proper security measures can significantly reduce the risk. Remember: in the era of artificial intelligence, trust is a luxury you cannot afford.
"AI technology can be both a tool and a weapon. How we use it depends on us – the users, manufacturers, and security experts."
— Ilja Viniecki, cybersecurity expert, Group-IB
If you use browsers with AI features, now is the time to verify your security. Before you fall victim to a bioshocking attack or a similar threat, take steps to protect yourself.
Read more about AI-related threats in the posts "Vulnerability in Microsoft 365 Copilot: Why blind trust in corporate AI is a mistake?" and "Sakana AI – what it is, how it works, and why it could change the future of AI".
Sources
- https://thehackernews.com/2026/06/new-bioshocking-attack-tricks-ai.html
- https://www.group-ib.com/media/bioshocking-attack/
- https://blog.chromium.org/2024/05/improving-extension-security.html
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38023
- https://blog.mozilla.org/addons/2024/06/10/ai-extensions-security/
- https://www.europol.europa.eu/media-press/newsroom/news/ai-powered-cyber-attacks-target-european-shoppers
- https://www.bleepingcomputer.com/news/security/ai-browser-extensions-used-to-steal-saas-credentials/
- https://www.slashnext.com/blog/wormgpt-the-generative-ai-tool-cybercriminals-are-used-to-launch-business-email-compromise-attacks/
- https://www.fbi.gov/news/stories/business-email-compromise-the-12-billion-scam
- https://csrc.nist.gov/projects/adversarial-machine-learning
- https://www.gartner.com/en/newsroom/press-releases/2024-04-10-gartner-predicts-30-percent-of-phishing-attacks-will-be-ai-powered-by-2025
- https://blog.checkpoint.com/2024/01/10/fraudgpt-the-dark-side-of-generative-ai/
Comments