Hacking

Malicious Chrome VPN Proxy Extensions Target Russian Users

Published  ·  5 min read

A massive set of 737 free VPN and proxy extensions have been discovered in the Chrome Web Store. Extensions mostly target the Russian speaking users seeking access to blocked services.

The malicious Chrome extensions have been developed to intercept browser traffic and route it through the attacker's own proxy infrastructure. Security researchers uncovered the campaign and its scale.

Let me break down the malicious Chrome VPN proxy extensions campaign and what users need to know.

Campaign Highlights

  • Malicious extensions found: 737 
  • Total number of installs: 75,486 
  • Extensions imitating 66 VPN brands: 274
  • The browser traffic route browser traffic through SOCKS5 proxies
  • All browser traffic is intercepted by the attackers
  • Extensions removed: 221 , active extensions: 516 
  • Russian speaking users targeted

Brands Impersonated

The malicious Chrome VPN proxy extensions impersonate well-known VPN and privacy brands:

  • Proton VPN
  • NordVPN
  • Surfshark
  • AdGuard VPN
  • Browsec
  • ExpressVPN
  • CyberGhost
  • Windscribe
  • TunnelBear
  • Cloudflare's 1.1.1.1
  • Google's Outline

How the Malicious Extensions Work

The malicious Chrome VPN proxy extensions set up a SOCKS5 proxy that intercepts all browser traffic:

Technical Details:

  • Extensions set chrome.proxy.settings to a fixed SOCKS5 server
  • The server runs on port 1082
  • Bypass list only includes loopback addresses (127.0.0.1)
  • Every other request is funneled through the proxy

What Attackers Can See:

  • Browser destinations
  • Source IP addresses
  • TLS SNI values
  • Any request body sent over plain HTTP

Adversary-in-the-Middle Position:

The attackers place themselves in an adversary-in-the-middle position. This means they can observe and potentially modify all traffic passing through the proxy.

Red Flags and Evasion Techniques

Some of the red flags in relation to these malicious Chrome extensions include:

Fake Features:

  • Promoting paid tiers which do not even exist
  • Premium locations which are not real
  • Entirely fake UI with animations

Evasion Techniques:

  • DNS-over-HTTPS blocklist evasion
  • Post-approval remote-configuration layer added
  • False statements to store reviewers
  • Identical justifications submitted

Internal Documents:

  • Internal manual named "Промт для сотрудников" (Prompt for employees)
  • Instructs developers to avoid putting domains directly in settings
  • Comments indicate deliberate policy evasion

The Russian Connection

The malicious Chrome VPN proxy extensions have links to Russia:

  • The threat actor runs a subscription VPN business in Russia
  • A 12-digit taxpayer number is associated with the operation
  • Some extensions leak Windows build paths with Russian folder names

Build Path Example:

C:\Users\ollob\OneDrive\Документы\1.myxa-work\08.06.26\<domain>\<product>\<product>-release.zip

Target Audience:

  • Primarily targets Russian-speaking users
  • Aims to provide access to blocked services
  • Extensions and descriptions are in Russian
  • Removed and Active Extensions

The current status of the malicious Chrome VPN proxy extensions:

  • 221 extensions removed from Chrome Web Store
  • 516 extensions remain active
  • 75,486 total installs recorded

The Core Infrastructure:

  • 520 of 522 extensions route traffic through the same SOCKS5 infrastructure
  • A single provider operates the proxy servers
  • The infrastructure may be resold from an upstream provider

The Clean-Then-Poisoned Extension

A separate incident highlights another pattern of malicious Chrome VPN proxy extensions:

"AI Sidebar with Deepseek, ChatGPT, Claude, and more":

  • Removed for Prompt Poaching tactics
  • Returned with a monetization scheme
  • Clean update removed data theft code
  • After 2 weeks, a new update added monetization

The Monetization Payload:

  • Opens an affiliate link in a foreground browser tab
  • Triggers on extension update events
  • Triggers on extension uninstall events
  • Suppresses DeepSeek user redirection to ChatGPT

What Users Should Do

Users of the malicious Chrome VPN proxy extensions should take action:

Immediate Steps:

  • Review installed Chrome extensions
  • Look for unknown VPN or proxy extensions
  • Check for brand impersonation (Proton, NordVPN, etc.)
  • Remove suspicious extensions immediately

How to Identify Malicious Extensions:

  • Check the developer account name
  • Look for Russian-language descriptions
  • Verify the extension's permissions
  • Check for recently added proxies

Safe Practices:

  • Only install extensions from trusted developers
  • Use official VPN applications, not browser extensions
  • Read reviews and check ratings
  • Monitor extension permissions

The Researcher Behind the Discovery

Security researcher Kush Pandya discovered the malicious Chrome VPN proxy extensions campaign. 

These findings are as follows:

  • 737 extensions from 40 different developers
  • 274 extensions impersonating 66 different brands
  • 75,486 installs in total
  • 221 extensions removed, 516 active

Key Findings:

  • "For each affected user, every request passes through a server the threat actor controls"
  • "What is established is the impersonation, the undisclosed proxy configuration, the non-existent premium servers, the false statements submitted to store reviewers, and the post-approval code substitution."

Wrapping It Up

The malicious Chrome VPN proxy extensions campaign is very dangerous for Chrome users, and more specifically, those who are looking to circumvent censorship, particularly those from Russia. The malware impersonate trusted brands and intercept all browser traffic.

Key points to remember:

  • 737 extensions impersonate 66 VPN brands
  • 75,486 installations detected
  • Extensions route traffic through proxies controlled by attackers
  • 221 removed, 516 remain
  • Russian-speaking users are the main target

Chrome users need to check their extensions right away. Uninstall all unknown proxy or VPN extensions. Do not install any extensions except from known developers.

This attack on malicious Chrome VPN proxy extensions reminds us about the security risks of browser extensions. Be careful.

FAQ Section

What are the malicious Chrome VPN proxy extensions?

They are 737 malicious extensions impersonating VPN brands like NordVPN and Proton VPN. They route the traffic from browsers through proxies controlled by the attacker.

How do the extensions work?

They configure the chrome.proxy.settings to use a proxy server using the SOCKS5 protocol on port 1082. All the traffic generated by the browser passes through the proxy server, thus giving the attacker an adversary-in-the-middle position.

Who is targeted?

The extensions primarily target users speaking the Russian language seeking access to blocked services. The descriptions and interfaces are in Russian.

Who are impersonating the brands?

Some of the brand names that have been impersonated include ProtonVPN, NordVPN, Surfshark, AdGuardVPN, ExpressVPN, CyberGhost, Windscribe, TunnelBear, Cloudflare 1.1.1.1, and Google Outline.

What should Chrome users do?

Immediately verify the list of installed extensions on their browser and remove all suspicious proxy or virtual private network extensions from their system. Install only reputable extension software. Use the apps rather than extensions.

Source: The Hacker News
Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067