HomeSecurityAI-Driven Phishing: Using browser permissions to collect data

AI-Driven Phishing: Use of browser permissions for data collection

A new phishing campaign leveraging artificial intelligence (AI) and uncovered by Cyble Research & Intelligence Labs (CRIL), shows how attackers are moving beyond traditional credential theft and adopting more invasive, technology-driven tactics. According to CRIL, the campaign has been active since early 2026 and relies on a wide range of techniques social engineering, with baits such as ID scanner, Telegram ID freezing and “Health Fund AI.

AI-Driven Phishing

These deceptive entry points are designed to trick users into granting access to hardware features, such as cameras and microphones, under the guise of account verification or recovery. Once permissions are granted, the malicious scripts begin collecting data.

This includes images, video recordings, microphone audio, device specifications, contact details, and geolocation. The stolen data is transmitted to systems controlled by the attackers via Telegram bots, making extraction fast and efficient. Researchers also noted signs of AI-assisted code generation in the campaign’s infrastructure.

See also: Konni Group exploits KakaoTalk to spread EndRAT Malware

AI phishing: Infrastructure and Attack Mechanism

The campaign primarily uses the edgeone.app to host phishing pages. These pages impersonate well-known platforms such as TikTok, Instagram, Telegram, Google Chrome, and even games like Flappy Bird to gain users’ trust.

Unlike traditional phishing attacks that rely on victims entering credentials, this AI-powered phishing campaign focuses on browser-level permissions.

Once a user interacts with a phishing page, the JavaScript code triggers permission requests. If they are accepted, the script activates the device's camera and begins capturing live data. A basic technique involves rendering a frame from a live video stream onto an HTML5 canvas using ctx.drawImage(). It then converts it to a JPEG file using canvas.toBlob().

This file is directly transmitted to the attackers via the Telegram Bot API. The same process is used for video and audio recordings.

See also: ClickFix attacks spread MacSync infostealer

AI-Driven Phishing: Use of browser permissions for data collection

Extended Data Collection Capabilities

The phishing framework goes beyond simple media capture. It performs extensive device fingerprinting using browser APIs such as: navigator.userAgent, navigator.platform, navigator.deviceMemory, navigator.hardwareConcurrency, navigator.connection, navigator.getBattery.

Through these methods, attackers collect detailed information about the victim's device, including the operating system, browser version, CPU capacity, RAM, network type, and battery status.

Additionally, the script retrieves the victim’s IP address via external services and enriches it with geographic data such as country, city, latitude, and longitude. This information is aggregated and sent to the attackers before further data collection. The campaign also attempts to access contact lists using the browser’s Contacts Picker API. If users give permission, names, phone numbers, and email addresses.

Role of Telegram in Data Exfiltration

A notable element of this campaign is its reliance on Telegram for command and control (C2) functions. By using Telegram bots, the attackers eliminate the need for complex backend infrastructure. Data such as images, videos, and audio files are sent directly via API methods such as sendPhoto, sendVideo, and sendAudio.

This approach simplifies operations while providing attackers with direct access to stolen information.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

User deception

To maintain credibility, phishing pages display realistic status messages such as “Photo Downloading,” “Sending to Server,” and “Photo Sent Successfully.” These messages mimic legitimate verification workflows, reinforcing the illusion of authenticity.

See also: Abuse of Microsoft Teams and Quick Assist to distribute A0Backdoor

Once the data is recorded and transmitted, the script disables the camera and resets the interface, leaving minimal visible traces of the attack.

AI-Driven Phishing: Use of browser permissions for data collection

Risks and Impacts on Businesses

The implications of this AI phishing campaign are significant. By collecting biometric and environmental data, attackers gain powerful tools for: Identity theft and account takeover, Bypassing verification systems video Targeted social engineering attacks, Blackmail using recorded media.

For example, images and recordings could be used to impersonate victims or bypass KYC (Know Your Customer) systems.

Device and location data allow attackers to create highly personalized attacks, increasing their success rate.

Organizations face additional risks, including reputational damage, regulatory non-compliance, and financial losses. The use of counterfeit trademarks further compounds the threat, eroding trust in legitimate digital services.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS