A novel agentic browser attack has been demonstrated against Perplexity's Comet browser, allowing attackers to delete the entire contents of a user's Google Drive through a zero-click technique. By leveraging the browser's integration with Gmail and Google Drive, and exploiting the excessive autonomy of LLM-powered assistants, attackers can send specially crafted emails containing natural language instructions. These instructions are interpreted as legitimate housekeeping tasks, resulting in the deletion of critical files without user confirmation, provided the agent has OAuth access to the relevant Google services.
Separately, the Predator spyware, developed by Intellexa, has adopted a new zero-click infection vector called "Aladdin," which delivers malware via malicious advertisements. This method targets specific individuals by serving weaponized ads through commercial ad networks, requiring only that the target views the ad for infection to occur. The infrastructure supporting this attack is distributed across multiple countries and leverages complex ad delivery mechanisms, making detection and attribution challenging. Both incidents highlight the growing sophistication and diversity of zero-click attack techniques targeting both browser automation and mobile devices.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
Cato Networks revealed the 'HashJack' technique, which hides malicious prompts in URL fragments to indirectly manipulate AI browser assistants. The disclosure noted that Perplexity and Microsoft patched affected browsers, while Google classified the issue as low severity and declined to fix it.
Researchers at Straiker STAR Labs found that a crafted email could abuse Perplexity's Comet browser integrations with Gmail and Google Drive to trigger deletion of a user's Google Drive without prompt injection or jailbreaks. The attack used natural-language instructions framed as legitimate housekeeping tasks, exposing a new zero-click risk in agentic browsers.
A joint investigation by Inside Story, Haaretz, and WAV Research Collective, corroborated by Amnesty International, Google, and Recorded Future, publicly detailed the Aladdin zero-click ad-based infection vector used by Predator spyware. The disclosure also highlighted leaked documents and prior research tying Intellexa to extensive zero-day exploitation.
Reporting cited in the reference says the Aladdin infection infrastructure and operations were still believed to be active as of 2024, despite sanctions and investigations into Intellexa. Researchers also identified additional Predator delivery vectors including 'Triton,' 'Thor,' and 'Oberon.'
Predator spyware operator Intellexa used a zero-click infection vector codenamed 'Aladdin' that infected targets when they viewed weaponized mobile ads delivered through commercial advertising networks. The campaign relied on identifiers such as public IP addresses to target victims and used infrastructure spread across multiple countries and shell companies to obscure operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.