All Articles

AI Hijacking & N0va Phishkit: 2026's Emerging Phishing Threats

September 17, 2026 5 min read By The Vici Tech Solutions Team
PhishingSocial EngineeringAI SecurityThreat Intelligence

The Phishing Landscape Has Shifted Again

September 2026 is proving that attackers aren't just refining old playbooks—they're writing entirely new ones. This week's threat intelligence reveals three distinct emerging attack patterns that every business needs to understand: AI assistant hijacking, sophisticated phishing kits targeting authentication flows, and browser extension-based credential theft. These aren't theoretical risks. They're active campaigns affecting organizations right now.

AI Assistant Hijacking: The BragJack Attack

Researchers at Forever Security discovered that a single malicious browser extension can hijack AI assistants built into Chrome, Comet, Edge, Opera Neon, and Claude. This attack vector, dubbed "BragJack" by Dark Reading, exploits the deep integration between browsers and their embedded AI tools.

The attack works because modern browsers grant their built-in AI assistants extensive permissions to read page content, interact with forms, and execute actions on behalf of users. A malicious extension that gains even ordinary permissions can intercept and manipulate these AI assistant sessions.

What makes this dangerous: Unlike traditional phishing, the victim doesn't need to click a suspicious link or download a fake attachment. Simply installing a seemingly benign browser extension—perhaps one that promises productivity features or ad blocking—can give attackers a foothold.

In a related incident, Mandiant reported that an attacker hijacked an AI coding assistant session at a SaaS provider and spread malware named Shai-Hulud across approximately 100 internal code repositories. The attack leveraged the assistant's authenticated session to propagate malicious code that appeared to come from a trusted development tool.

Red Flags and Defenses

Warning signs:

  • Browser extensions requesting permissions to "read and change all your data on websites you visit"
  • AI assistant behavior that seems off—suggesting actions you didn't request or accessing data outside your current context
  • Unexpected code suggestions or repository commits from AI coding tools

Concrete defenses:

  • Audit all installed browser extensions quarterly. Remove anything not actively used.
  • Implement extension allowlists in enterprise environments using group policy or mobile device management
  • Disable AI assistants in browsers used for sensitive work, or use separate browser profiles
  • Monitor AI coding assistant activity logs for unusual repository access patterns
  • Require code review for all AI-generated commits, even from trusted tools

N0va Phishkit: Authentication Flow Abuse at Scale

The N0va phishing kit is targeting US and EU organizations with campaigns that impersonate trusted services and abuse legitimate authentication flows. This isn't your grandfather's phishing email with a misspelled domain and poor grammar.

N0va campaigns create pixel-perfect replicas of Microsoft 365, Google Workspace, and other enterprise authentication pages. More critically, they proxy authentication requests in real-time—a technique called adversary-in-the-middle (AitM) phishing. When a victim enters credentials and completes multi-factor authentication, the kit captures both the password and the active session token.

Why this matters: Session token theft bypasses MFA entirely. The attacker doesn't need your password after the initial compromise—they have a valid authenticated session that looks identical to your legitimate login.

Red Flags and Defenses

Warning signs:

  • Login pages reached through email links, even if the URL looks correct (attackers use homoglyphs and punycode)
  • Unexpected MFA prompts, especially push notifications you didn't initiate
  • Browser security warnings about certificate mismatches, even briefly
  • Login pages that load slightly slower than usual (real-time proxying introduces latency)

Concrete defenses:

  • Train employees to manually type URLs for authentication pages, never clicking email links
  • Deploy phishing-resistant MFA like FIDO2 security keys or passkeys that bind authentication to specific domains
  • Implement conditional access policies that flag logins from unusual locations or devices
  • Monitor for impossible travel scenarios—a user can't log in from New York and Singapore five minutes apart
  • Use browser isolation technology for high-risk users (executives, finance, HR)
  • Enable token binding and implement short session timeouts for sensitive applications

Browser Extension Malware: The KREMLIN Toolkit

A banking malware operation using the KREMLIN toolkit has been active since mid-2025, forcibly installing malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. The toolkit bypasses normal browser security checks that should prevent unauthorized extension installation.

This attack typically begins with a different initial infection vector—a trojanized installer, malicious email attachment, or compromised website. Once the malware gains a foothold, it manipulates browser configuration files and policies to silently install extensions that appear legitimate.

Red Flags and Defenses

Warning signs:

  • Extensions appearing in your browser that you don't remember installing
  • Browser settings or policies that won't change when you modify them (indicating external control)
  • Antivirus warnings about browser-related files or registry keys
  • Unexpected browser performance degradation or network activity

Concrete defenses:

  • Enable tamper protection in endpoint security tools to prevent unauthorized changes to browser configurations
  • Use application allowlisting to prevent unauthorized software installation
  • Regularly review installed extensions in all browsers: Chrome (chrome://extensions), Edge (edge://extensions)
  • Implement network monitoring to detect unusual outbound connections from browser processes
  • Keep browsers updated—extension security controls improve with each release

The Social Engineering Element

All three attack patterns share a common thread: they exploit trust. AI assistants are trusted tools. Authentication pages from known services are trusted interfaces. Browser extensions promise trusted functionality.

Modern phishing isn't about fooling users with obvious fakes. It's about hijacking legitimate channels and trusted tools. The best technical defenses fail if users don't understand the threat model.

Essential training topics for 2026:

  • How AI assistants can be compromised and what that access enables
  • Why MFA alone isn't sufficient against AitM attacks
  • The difference between phishing-resistant and phishing-susceptible authentication methods
  • How to verify you're on a legitimate authentication page (check the padlock, examine the full URL, use bookmarks)
  • The importance of reporting suspicious activity immediately, even if you're not sure

Immediate Action Items

Based on this week's threat intelligence:

  1. Audit browser extensions across your organization this week
  2. Evaluate your MFA implementation—are you using phishing-resistant methods for sensitive systems?
  3. Update security awareness training to cover AI assistant risks and AitM phishing
  4. Review authentication logs for unusual patterns that might indicate token theft
  5. Implement conditional access policies if you haven't already
  6. Test your incident response plan for a scenario involving compromised AI tools or stolen session tokens

The threat landscape continues to evolve faster than many organizations can adapt. Understanding these emerging attack patterns and implementing layered defenses isn't optional—it's the baseline for operating securely in 2026.

If you need help assessing your organization's resilience against these emerging threats or want to test your defenses through realistic phishing simulations and penetration testing, Vici Tech Solutions can help.

Worried about the threats you just read about?

Vici Tech Solutions helps businesses across the US find and fix vulnerabilities before attackers do. Explore our penetration testing services or talk to us about your security posture.

Get a Security Assessment