A recent investigation has uncovered a significant security threat involving 737 free VPN and proxy extensions on the Chrome Web Store, primarily targeting Russian-speaking users. These extensions, which have amassed over 75,000 installs, are designed to intercept browser traffic and route it through a proxy infrastructure, raising serious privacy concerns. According to research from The Hacker News, many of these extensions impersonate well-known VPN brands such as Proton VPN and NordVPN.
Security researcher Kush Pandya noted that the majority of these extensions route users’ entire browser sessions through a fixed SOCKS5 server, effectively placing the threat actor in an adversary-in-the-middle (AitM) position. This allows them to monitor browser destinations, source IP addresses, and any unencrypted HTTP request data.
Out of the 737 extensions, 221 have already been removed from the Chrome Web Store, while 516 remain active. The threat actor is believed to be operating a subscription VPN service in Russia, as indicated by a leaked taxpayer number and other identifiable information.
Red Flags and Malicious Behavior
The extensions exhibit several alarming characteristics that suggest malicious intent:
- They advertise non-existent premium features.
- They employ tactics to evade DNS-over-HTTPS blocklists.
- They display fake interfaces while failing connection attempts.
- They include internal manuals instructing developers on how to obscure their activities.
- They attempt to manipulate the Chrome Web Store review process with misleading claims.
While the functionality of these extensions may appear similar to legitimate VPN services, the deceptive practices and the impersonation of established brands highlight a significant threat to user privacy and security.
Ongoing Developments
In a related development, Netskope Threat Labs reported the resurgence of a previously removed Chrome extension, “AI Sidebar with Deepseek, ChatGPT, Claude, and more,” which had engaged in data theft tactics. This extension has now introduced a monetization scheme that opens affiliate links during updates and uninstalls, further complicating the landscape of browser security.
As investigations continue, users are advised to exercise caution when installing VPN and proxy extensions, particularly those that claim to offer premium services without clear verification.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.


