A massive set of 737 free VPN and proxy extensions have been discovered in the Chrome Web Store. Extensions mostly target the Russian speaking users seeking access to blocked services.
The malicious Chrome extensions have been developed to intercept browser traffic and route it through the attacker's own proxy infrastructure. Security researchers uncovered the campaign and its scale.
Let me break down the malicious Chrome VPN proxy extensions campaign and what users need to know.
Campaign Highlights
- Malicious extensions found: 737
- Total number of installs: 75,486
- Extensions imitating 66 VPN brands: 274
- The browser traffic route browser traffic through SOCKS5 proxies
- All browser traffic is intercepted by the attackers
- Extensions removed: 221 , active extensions: 516
- Russian speaking users targeted
Brands Impersonated
The malicious Chrome VPN proxy extensions impersonate well-known VPN and privacy brands:
- Proton VPN
- NordVPN
- Surfshark
- AdGuard VPN
- Browsec
- ExpressVPN
- CyberGhost
- Windscribe
- TunnelBear
- Cloudflare's 1.1.1.1
- Google's Outline
How the Malicious Extensions Work
The malicious Chrome VPN proxy extensions set up a SOCKS5 proxy that intercepts all browser traffic:
Technical Details:
- Extensions set chrome.proxy.settings to a fixed SOCKS5 server
- The server runs on port 1082
- Bypass list only includes loopback addresses (127.0.0.1)
- Every other request is funneled through the proxy
What Attackers Can See:
- Browser destinations
- Source IP addresses
- TLS SNI values
- Any request body sent over plain HTTP
Adversary-in-the-Middle Position:
The attackers place themselves in an adversary-in-the-middle position. This means they can observe and potentially modify all traffic passing through the proxy.
Red Flags and Evasion Techniques
Some of the red flags in relation to these malicious Chrome extensions include:
Fake Features:
- Promoting paid tiers which do not even exist
- Premium locations which are not real
- Entirely fake UI with animations
Evasion Techniques:
- DNS-over-HTTPS blocklist evasion
- Post-approval remote-configuration layer added
- False statements to store reviewers
- Identical justifications submitted
Internal Documents:
- Internal manual named "Промт для сотрудников" (Prompt for employees)
- Instructs developers to avoid putting domains directly in settings
- Comments indicate deliberate policy evasion
The Russian Connection
The malicious Chrome VPN proxy extensions have links to Russia:
- The threat actor runs a subscription VPN business in Russia
- A 12-digit taxpayer number is associated with the operation
- Some extensions leak Windows build paths with Russian folder names
Build Path Example:
C:\Users\ollob\OneDrive\Документы\1.myxa-work\08.06.26\<domain>\<product>\<product>-release.zip
Target Audience:
- Primarily targets Russian-speaking users
- Aims to provide access to blocked services
- Extensions and descriptions are in Russian
- Removed and Active Extensions
The current status of the malicious Chrome VPN proxy extensions:
- 221 extensions removed from Chrome Web Store
- 516 extensions remain active
- 75,486 total installs recorded
The Core Infrastructure:
- 520 of 522 extensions route traffic through the same SOCKS5 infrastructure
- A single provider operates the proxy servers
- The infrastructure may be resold from an upstream provider
The Clean-Then-Poisoned Extension
A separate incident highlights another pattern of malicious Chrome VPN proxy extensions:
"AI Sidebar with Deepseek, ChatGPT, Claude, and more":
- Removed for Prompt Poaching tactics
- Returned with a monetization scheme
- Clean update removed data theft code
- After 2 weeks, a new update added monetization
The Monetization Payload:
- Opens an affiliate link in a foreground browser tab
- Triggers on extension update events
- Triggers on extension uninstall events
- Suppresses DeepSeek user redirection to ChatGPT
What Users Should Do
Users of the malicious Chrome VPN proxy extensions should take action:
Immediate Steps:
- Review installed Chrome extensions
- Look for unknown VPN or proxy extensions
- Check for brand impersonation (Proton, NordVPN, etc.)
- Remove suspicious extensions immediately
How to Identify Malicious Extensions:
- Check the developer account name
- Look for Russian-language descriptions
- Verify the extension's permissions
- Check for recently added proxies
Safe Practices:
- Only install extensions from trusted developers
- Use official VPN applications, not browser extensions
- Read reviews and check ratings
- Monitor extension permissions
The Researcher Behind the Discovery
Security researcher Kush Pandya discovered the malicious Chrome VPN proxy extensions campaign.
These findings are as follows:
- 737 extensions from 40 different developers
- 274 extensions impersonating 66 different brands
- 75,486 installs in total
- 221 extensions removed, 516 active
Key Findings:
- "For each affected user, every request passes through a server the threat actor controls"
- "What is established is the impersonation, the undisclosed proxy configuration, the non-existent premium servers, the false statements submitted to store reviewers, and the post-approval code substitution."
Wrapping It Up
The malicious Chrome VPN proxy extensions campaign is very dangerous for Chrome users, and more specifically, those who are looking to circumvent censorship, particularly those from Russia. The malware impersonate trusted brands and intercept all browser traffic.
Key points to remember:
- 737 extensions impersonate 66 VPN brands
- 75,486 installations detected
- Extensions route traffic through proxies controlled by attackers
- 221 removed, 516 remain
- Russian-speaking users are the main target
Chrome users need to check their extensions right away. Uninstall all unknown proxy or VPN extensions. Do not install any extensions except from known developers.
This attack on malicious Chrome VPN proxy extensions reminds us about the security risks of browser extensions. Be careful.
FAQ Section
What are the malicious Chrome VPN proxy extensions?
They are 737 malicious extensions impersonating VPN brands like NordVPN and Proton VPN. They route the traffic from browsers through proxies controlled by the attacker.
How do the extensions work?
They configure the chrome.proxy.settings to use a proxy server using the SOCKS5 protocol on port 1082. All the traffic generated by the browser passes through the proxy server, thus giving the attacker an adversary-in-the-middle position.
Who is targeted?
The extensions primarily target users speaking the Russian language seeking access to blocked services. The descriptions and interfaces are in Russian.
Who are impersonating the brands?
Some of the brand names that have been impersonated include ProtonVPN, NordVPN, Surfshark, AdGuardVPN, ExpressVPN, CyberGhost, Windscribe, TunnelBear, Cloudflare 1.1.1.1, and Google Outline.
What should Chrome users do?
Immediately verify the list of installed extensions on their browser and remove all suspicious proxy or virtual private network extensions from their system. Install only reputable extension software. Use the apps rather than extensions.