Illustration of a web browser with a VPN extension icon, highlighting security threats and data interception.
Uncategorized

Digital Deception: Hundreds of Malicious Chrome VPN Extensions Exposed, Threatening User Privacy

Share
Share
Pinterest Hidden

In a stark reminder of the ever-present dangers lurking in the digital realm, a staggering 737 free VPN and proxy extensions for Google Chrome have been uncovered, primarily targeting Russian-speaking users. These deceptive tools, masquerading as legitimate services, were designed to intercept browser traffic and reroute it through a covert proxy infrastructure, exposing users to significant privacy risks.

The Deceptive Web: Hundreds of Malicious Chrome VPN Extensions Exposed

The extensive network of malicious extensions, spread across at least 40 different Chrome Web Store developer accounts, managed to accumulate a worrying 75,486 installs before detection. Alarmingly, 274 of these extensions were found to be impersonating 66 well-known VPN and privacy brands. Prestigious names like Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec, ExpressVPN, CyberGhost, Windscribe, TunnelBear, Cloudflare’s 1.1.1.1, and Google’s Outline were all mimicked in this elaborate scheme, as reported by security firm Socket.

A Deep Dive into the Deception

Security researcher Kush Pandya revealed that these “censorship circumvention” extensions were engineered to “route the user’s entire browser session through SOCKS5 proxies operated by a single provider.” A staggering 520 out of 522 extensions analyzed in a bulk corpus were found to utilize the identical SOCKS5 infrastructure. This setup effectively places the threat actor in an adversary-in-the-middle (AitM) position, granting them the ability to observe critical user data, including browser destinations, source IP addresses, TLS SNI values, and any unencrypted request bodies sent over plain HTTP.

The mechanism behind this interception is insidious: most extensions configure chrome.proxy.settings to a fixed SOCKS5 server on port 1082. While a bypass list is included, it exclusively contains loopback addresses (e.g., 127.0.0.1), ensuring that virtually all other browser requests are funneled through the malicious SOCKS5 relay once the user believes they’ve connected to a legitimate VPN service.

Unmasking the Threat Actor and Red Flags

While 221 of these rogue browser add-ons have since been removed from the Chrome Web Store, a concerning 516 extensions remained active at the time of the report. Investigations suggest the threat actor operates a subscription VPN business in Russia, with clues pointing to a 12-digit taxpayer number and leaked Windows build paths (e.g.,

C:UsersollobOneDriveДокументы1.myxa-work8.06.26-release.zip).

The defining characteristic of this operation is not the proxy functionality itself, which can be legitimate, but the brazen attempt to impersonate established brands rather than operating under their own name. Numerous red flags further expose the malicious intent:

  • Advertising non-existent paid tiers or premium locations.
  • Employing DNS-over-HTTPS blocklist evasion techniques.
  • Displaying fully functional fake interfaces, including connection animations and status indicators, despite failing every actual connection attempt.
  • Shipping an internal manual, “Промт для сотрудников” (Prompt for employees), which explicitly instructs staff to avoid directly inputting domains into chrome.proxy.settings and to refrain from using domains from another extension without specific instructions.
  • Presence of code comments indicating deliberate attempts to circumvent Chrome Web Store policies.
  • Adding new remote-configuration layers post-extension approval.
  • Attempts to manipulate the Chrome Web Store review process with identical, false justifications like “No data transmitted to external servers” or “No user tracking or logging.”

“For each affected user, while the extension is connected, every request passes through a server the threat actor controls,” Pandya emphasized. This means whether the threat actor owns the proxy servers or resells capacity, a third party is always in a position to observe user traffic. The core issues remain the impersonation, the undisclosed proxy configuration, the fabricated premium services, the false statements to reviewers, and the post-approval code substitutions.

A Troubling Trend: The Return of ‘AI Sidebar’ with a New Scheme

This discovery coincides with another concerning development highlighted by Netskope Threat Labs: the reappearance of the Google Chrome extension “AI Sidebar with Deepseek, ChatGPT, Claude, and more.” This extension had previously been removed for “Prompt Poaching” tactics. After a seemingly benign update that removed the data theft code and acknowledged wrongdoing, the extension resurfaced with a new monetization scheme. This “clean-then-poisoned” update, deployed via Google’s CRX content delivery network, introduced a “surgical” 21-line addition that triggers an affiliate link to open in a foreground browser tab every time the extension updates or uninstalls. It also suppresses the redirection of DeepSeek users to ChatGPT, indicating a deliberate manipulation of user experience for financial gain.

These incidents underscore the critical importance of vigilance when installing browser extensions. Users are urged to scrutinize developer legitimacy, review permissions carefully, and stick to well-known, reputable brands to protect their digital privacy and security.


For more details, visit our website.

Source: Link

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *