SearchJack Campaign Hijacks 758,000 Users with 23 Malicious Chrome Extensions
Key Takeaways A sophisticated campaign, dubbed “SearchJack,” exploited 23 malicious Chrome extensions to surreptitiously redirect the search queries of approximately 758,000 users. These...
Key Takeaways
- A sophisticated campaign, dubbed “SearchJack,” exploited 23 malicious Chrome extensions to surreptitiously redirect the search queries of approximately 758,000 users.
- These extensions masqueraded as legitimate tools but silently altered default search settings, routing user queries through undisclosed monetization systems.
- The operators leveraged Chrome’s
chrome_settings_overridesfeature, making the hijacking difficult for average users to detect. - The campaign poses a significant security risk beyond mere adware, as operators could pivot to delivering phishing content or malicious downloads without requiring extension updates.
A widespread and clandestine operation, now identified as “SearchJack,” has compromised the search activities of nearly three-quarters of a million Chrome users globally. This campaign utilized a network of 23 seemingly innocuous browser extensions to reroute search queries through hidden revenue-generating mechanisms, all without the users’ knowledge or consent.
Table Of Content
Each of the malicious extensions presented itself as a beneficial utility, ranging from satellite mapping tools to productivity applications. However, their primary function was to silently execute a search hijacking scheme in the background, funneling user data through a series of intermediary servers before displaying seemingly normal search results.
How SearchJack Operates
The core mechanism of the SearchJack campaign is both simple and remarkably difficult to detect. Upon installation, these extensions exploit a legitimate Chrome feature, chrome_settings_overrides, to forcibly change the browser’s default search engine. When a user subsequently initiates a search, their query is first directed through servers controlled by the campaign’s operators. This process adds a monetization layer to every search, a step entirely hidden from the user, before the query finally reaches its intended destination, typically Yahoo, displaying what appears to be an unadulterated search results page. For a detailed technical analysis, refer to the report by MalExt Sentry.
The campaign was brought to light by researchers at MalExt Sentry, who utilized their automated scanning system to monitor Chrome extension listings for suspicious activities. According to their report shared with Cyber Security News (CSN), the scanner specifically identified extensions that were misusing the chrome_settings_overrides manifest key to seize control of browser search settings.
MalExt Sentry’s investigation uncovered at least eight distinct affiliate brokers involved in the campaign, each uniquely identified by a specific tracking parameter appended to the final Yahoo redirect URL. This network of brokers is crucial to the campaign’s monetization strategy.
Deceptive Practices and Privacy Concerns
A significant challenge in detecting SearchJack lies in the discrepancy between the extensions’ advertised functionality and their actual behavior. For instance, the extension “Nautilus Search” explicitly claimed in its Chrome Web Store listing that it would neither track searches nor collect personal data. However, its linked privacy policy directly contradicted this, revealing that it collected IP addresses, search queries, and device identifiers.
This deliberate misrepresentation is not merely an oversight; it constitutes a false claim that could potentially lead to legal action under regulations such as GDPR and FTC frameworks. The broad scope of this campaign raises serious concerns that extend beyond misleading descriptions. Because the operators maintain control over where search traffic is directed, they possess the ability to covertly shift from delivering standard search results to serving malicious content, such as phishing pages or drive-by downloads, without needing to push any updates to the installed extensions. This inherent capability to escalate harm, without altering the visible code, transforms SearchJack from simple adware into a significant cybersecurity threat.
The Technical Architecture of SearchJack
The SearchJack campaign’s technical infrastructure is designed for stealth, employing a multi-layered redirect system. Many of the identified extensions are “shell extensions,” containing minimal code beyond the manifest file that reconfigures the default search engine. These extensions typically lack background scripts, do not request overt permissions, and offer no visual cues of their malicious activity. A common structural template is observed across numerous extensions, with only the domain and icon being altered to create new variants.
A smaller subset of these extensions incorporates rudimentary, fake functionalities, such as basic map viewers or video libraries. These superficial features serve to bypass automated review processes in the Chrome Web Store and to lend an air of legitimacy to the installation. While largely non-functional, they are sufficient to prevent immediate removal. For example, the “Search Toggler” extension presents users with an interface that purports to allow switching between different search engines. In reality, all queries are still routed through the operator’s servers, irrespective of the user’s selection. The critical routing logic is injected at runtime, making it invisible to conventional static analysis tools.
The Broker Network Enabling the Campaign
At the heart of the SearchJack campaign lies a network of brokers, each operating under a revenue-sharing agreement with Yahoo’s search affiliate program. These brokers earn a commission for every search query routed through their system. The campaign involves at least eight distinct brokers, with a substantial portion of the activity linked to an unidentified operator.
While some brokers, like Dublin-based Becovi Ltd, have a traceable identity, others remain anonymous, complicating efforts for accountability and enforcement. An intriguing case involves “Fusebase Search,” an extension published under a legitimate company name, which displayed 609 reviews against a mere 490 current installations. This statistically improbable ratio suggests either sophisticated review manipulation or a prior policy violation that led to a reset of its installation count.
Researchers advocate for enforcement actions to target the broker level rather than individual extensions. This strategy is based on the understanding that while extensions are easily replaced, the underlying affiliate accounts represent a more persistent vulnerability. Users are strongly advised to regularly audit their installed extensions, remove any unfamiliar or suspicious items, and manually verify and reset their default search engine settings within Chrome.
What You Should Do
- Audit Your Extensions: Regularly review all installed Chrome extensions. Remove any extensions that seem unfamiliar, were installed without your explicit intent, or offer functionality you no longer need.
- Verify Search Settings: Manually check your default search engine in Chrome’s settings. Navigate to
chrome://settings/searchand ensure your preferred search engine is selected. If it has been changed without your knowledge, reset it. - Be Skeptical of “Free” Tools: Exercise caution when installing new browser extensions, especially those offering free services like maps, video libraries, or productivity tools. Always scrutinize their privacy policies, even if the store description seems benign.
- Report Suspicious Extensions: If you identify an extension exhibiting behavior similar to SearchJack, report it to the Chrome Web Store.
- Consider Browser Security Tools: Utilize browser security extensions or anti-malware software that specifically monitors for browser hijacks and unwanted program installations.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | myperfecttab[.]com | PerfecTab Search redirect domain |
| Domain | query.quicksearchtool[.]com | Quick Search Tool redirect domain |
| Domain | search.getbettersearch-api[.]com | Better Search redirect domain |
| Domain | newtab[.]club | NewTab.Search redirect domain |
| Domain | nautilus-notes[.]com | Nautilus Search redirect domain |
| Domain | earthapp[.]net | Earth extension redirect domain (infospace broker) |
| Domain | wanderlustar[.]com | Wanderlustar redirect domain |
| Domain | services.templatesearchsvc[.]org | Template Search redirect domain |
| Domain | earth3d[.]net | Earth 3D redirect domain (infospace broker) |
| Domain | myfocalfind[.]com | My Focal Find redirect domain |
| Domain | greatstartapp[.]com | Great Start redirect domain (becovi broker) |
| Domain | freshfruittab[.]com | Fresh Fruit Search redirect domain |
| Domain | viewmenuprices[.]com | View Menu with Prices redirect domain (infospace broker) |
| Domain | searchtoggler[.]com | Search Toggler operator domain |
| Domain | loginonlineapp[.]com | Easy Login redirect domain (infospace broker) |
| Domain | seek.searchthatweb[.]com | SearchThatWeb redirect domain |
| Domain | search.freshysearchapi[.]net | Freshy Search redirect domain (trp broker) |
| Domain | myvideolibrary[.]info | Video Search Extension redirect domain |
| Domain | bestfreemaps[.]com | Get Maps & Driving Directions + Satelliten Earth redirect domain |
| Domain | searchanything[.]co | Search Anything redirect domain (mnet broker) |
| Domain | oasrchrdr[.]com | Surfer Search redirect domain (fc broker) |
| Domain | s.fusebasesearch[.]com | Fusebase Search redirect domain (dcola broker) |
| Domain | worthathousandwords[.]com | Search Toggler contact email domain |
| Extension ID | hohedjmdoemgcpgdapepfhnilbedldnm | PerfecTab Search (Chrome Extension ID) |
| Extension ID | keadechokmcohlcampccppbjjeabghcd | Quick Search Tool (Chrome Extension ID) |
| Extension ID | epdmngmgidehpmhjamdjcaecpligmcfh | Better Search (Chrome Extension ID) |
| Extension ID | pookachmhghnpgjhebhilcidgdphdlhi | NewTab.Search (Chrome Extension ID) |
| Extension ID | flcaigefphghbcgbmfngbfdgipdflfpn | Nautilus Search (Chrome Extension ID) |
| Extension ID | hnfdneofpohlkoeljnmkdocokcdk jiaa | Earth (Chrome Extension ID) |
| Extension ID | bgliakflmjnofiolfmnbncdmgfnibgnj | Wanderlustar (Chrome Extension ID) |
| Extension ID | cnkcgoiimpncbonlilkekbigfhchcbgb | Template Search (Chrome Extension ID) |
| Extension ID | kbobdmmjbaljcombpliahadgoafgohcd | Earth 3D (Chrome Extension ID) |
| Extension ID | eeejfmalgedffijdepcdmgemfnadjefe | My Focal Find (Chrome Extension ID) |
| Extension ID | mccmkaicbneobeclkbloeoopcfeipmio | Great Start (Chrome Extension ID) |
| Extension ID | jeookppofphgjnhjkifeejcmjbpiogka | Fresh Fruit Search (Chrome Extension ID) |
| Extension ID | ijbmkpeacbkgpfkomjbionjgdhbmlpfp | View Menu with Prices (Chrome Extension ID) |
| Extension ID | hodgcolihbmeagfcfpdfpnapfflmpbkb | Search Toggler (Chrome Extension ID) |
| Extension ID | cpmjnpalighpdecgankobogpcmbceaig | Easy Login (Chrome Extension ID) |
| Extension ID | akimdaijebpdfo jiohhimbebkdigkccj | SearchThatWeb (Chrome Extension ID) |
| Extension ID | oikgbpcmdphfkhplgkfngjilemlo lann | Freshy Search (Chrome Extension ID) |
| Extension ID | efakcomgmimcekdejnoafmmbgnpdhdfm | Video Search Extension (Chrome Extension ID) |
| Extension ID | gmapdckphdmbafmmcfoahhgoogdjeell | Get Maps & Driving Directions (Chrome Extension ID) |
| Extension ID | odafhekandnacimkenmaagnoemnpaakk | Search Anything (Chrome Extension ID) |
| Extension ID | jgoihmjphghpnjedflgemmhjdaogimad | Satelliten Earth (Chrome Extension ID) |
| Extension ID | dllhnjhfilgcjopkgdekmdmfilpfceig | Surfer Search (Chrome ID) |
| Extension ID | ododhdcefemfdbnidbeipjpjaehadjen | Fusebase Search (Chrome Extension ID) |
| URL Parameter | hspart=trp | Broker tracking parameter — unknown operator |
| URL Parameter | hspart=infospace | Broker tracking parameter — System1 |
| URL Parameter | hspart=flowsurf | Broker tracking parameter — unknown operator |
| URL Parameter | hspart=adk | Broker tracking parameter — unknown operator |
| URL Parameter | hspart=becovi | Broker tracking parameter — Becovi Ltd, Dublin |
| URL Parameter | hspart=imageadvan | Broker tracking parameter — unknown operator |
| URL Parameter | hspart=mnet | Broker tracking parameter — unknown operator |
| URL Parameter | hspart=fc | Broker tracking parameter — unknown operator |
| URL Parameter | hspart=dcola | Broker tracking parameter — unknown operator |
| edgarlife1980[@]gmail[.]com | Publisher account for Earth 3D extension |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.