Over 737 fake Chrome VPN extensions, masquerading as well-known brands such as Proton VPN and NordVPN, have been discovered routing users’ traffic through SOCKS5 proxies operated by a single provider. This malicious campaign has resulted in nearly 75,000 downloads from the Chrome Web Store, with a significant number of victims hailing from Russia.
The extensions, which impersonated popular VPN services, configured Chrome to route all browser traffic through the operator’s SOCKS5 proxies on port 1082. This setup allowed the threat actor’s server to intercept and monitor every destination, TLS SNI value, source IP, and request body sent over plain HTTP. In some cases, the extensions even resolved their proxy hostnames through Cloudflare or Google DNS-over-HTTPS to protect the operator’s domain from scrutiny.
The campaign appears to be an attempt to funnel customers into a subscription-based VPN service in Russia. The researchers identified several indicators of intentional deception, including impersonating well-known brands, advertising nonexistent premium server locations, and using nonfunctional payment or connection mechanisms. Additionally, some extensions were found to have misleading disclosures to store reviewers and added remote configuration after being approved.
The fact that over 500 of these fake extensions are still available in the Chrome Web Store raises concerns about the effectiveness of Google’s security measures. While Google did remove more than 200 extensions related to the identified campaign, it seems that many others were able to evade detection. This highlights the need for users to remain vigilant and take proactive steps to protect themselves from such threats.
One of the key takeaways from this incident is the importance of verifying the authenticity of VPN services before subscribing to them. Users should always check the extension’s description, reviews, and ratings before installing it, and be wary of extensions that offer premium servers in locations that seem too good (or convenient) to be true. Furthermore, users should regularly review their browser’s proxy configuration to ensure that it has not been tampered with.
Ultimately, this incident serves as a reminder that the security landscape is constantly evolving, and users must stay informed and proactive to protect themselves from emerging threats. By being aware of these tactics and taking steps to mitigate them, we can reduce our vulnerability to such attacks and maintain online safety.
Source: Bleeping Computer — 2026-08-12