737 Chrome VPN Extensions Found Routing Traffic Through Proxies, Targeting Users

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

A recent investigation has uncovered a significant security threat involving 737 free VPN and proxy extensions on the Chrome Web Store, primarily targeting Russian-speaking users. These extensions, which have amassed over 75,000 installs, are designed to intercept browser traffic and route it through a proxy infrastructure, raising serious privacy concerns. According to research from The Hacker News, many of these extensions impersonate well-known VPN brands such as Proton VPN and NordVPN.

Security researcher Kush Pandya noted that the majority of these extensions route users’ entire browser sessions through a fixed SOCKS5 server, effectively placing the threat actor in an adversary-in-the-middle (AitM) position. This allows them to monitor browser destinations, source IP addresses, and any unencrypted HTTP request data.

Out of the 737 extensions, 221 have already been removed from the Chrome Web Store, while 516 remain active. The threat actor is believed to be operating a subscription VPN service in Russia, as indicated by a leaked taxpayer number and other identifiable information.

Red Flags and Malicious Behavior

The extensions exhibit several alarming characteristics that suggest malicious intent:

  • They advertise non-existent premium features.
  • They employ tactics to evade DNS-over-HTTPS blocklists.
  • They display fake interfaces while failing connection attempts.
  • They include internal manuals instructing developers on how to obscure their activities.
  • They attempt to manipulate the Chrome Web Store review process with misleading claims.

While the functionality of these extensions may appear similar to legitimate VPN services, the deceptive practices and the impersonation of established brands highlight a significant threat to user privacy and security.

Ongoing Developments

In a related development, Netskope Threat Labs reported the resurgence of a previously removed Chrome extension, “AI Sidebar with Deepseek, ChatGPT, Claude, and more,” which had engaged in data theft tactics. This extension has now introduced a monetization scheme that opens affiliate links during updates and uninstalls, further complicating the landscape of browser security.

As investigations continue, users are advised to exercise caution when installing VPN and proxy extensions, particularly those that claim to offer premium services without clear verification.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

IDScan Confirms Data Breach Exposing 153 Million Driver’s License Scans for Sale on Dark Web

Identity verification firm IDScan has confirmed a data breach that has exposed scans of approximately 153 million driver’s licenses, with the information reportedly available...

NVIDIA and Palantir Collaborate to Enhance Supply Chain Sovereignty with AI Solutions

Palantir Technologies Inc. and NVIDIA have announced a strategic collaboration aimed at enhancing supply chain sovereignty through advanced artificial intelligence (AI) solutions. This partnership...

Microsoft Warns of AI-Enhanced Executive Impersonation and Invoice Fraud Campaigns

In a concerning trend, threat actors are leveraging artificial intelligence (AI) to enhance their tactics in executing executive impersonation and invoice fraud schemes. Recent...

NASA’s SARSAT technology aids in rescue of five fishermen at sea

NASA's Search and Rescue Satellite-Aided Tracking (SARSAT) technology played a crucial role in the rescue of five fishermen off the Gulf Coast of Mississippi...