737 Chrome VPN Extensions Found Routing Traffic Through Proxies, Targeting Users

Published:

spot_img

A recent investigation has uncovered a significant security threat involving 737 free VPN and proxy extensions on the Chrome Web Store, primarily targeting Russian-speaking users. These extensions, which have amassed over 75,000 installs, are designed to intercept browser traffic and route it through a proxy infrastructure, raising serious privacy concerns. According to research from The Hacker News, many of these extensions impersonate well-known VPN brands such as Proton VPN and NordVPN.

Security researcher Kush Pandya noted that the majority of these extensions route users’ entire browser sessions through a fixed SOCKS5 server, effectively placing the threat actor in an adversary-in-the-middle (AitM) position. This allows them to monitor browser destinations, source IP addresses, and any unencrypted HTTP request data.

Out of the 737 extensions, 221 have already been removed from the Chrome Web Store, while 516 remain active. The threat actor is believed to be operating a subscription VPN service in Russia, as indicated by a leaked taxpayer number and other identifiable information.

Red Flags and Malicious Behavior

The extensions exhibit several alarming characteristics that suggest malicious intent:

  • They advertise non-existent premium features.
  • They employ tactics to evade DNS-over-HTTPS blocklists.
  • They display fake interfaces while failing connection attempts.
  • They include internal manuals instructing developers on how to obscure their activities.
  • They attempt to manipulate the Chrome Web Store review process with misleading claims.

While the functionality of these extensions may appear similar to legitimate VPN services, the deceptive practices and the impersonation of established brands highlight a significant threat to user privacy and security.

Ongoing Developments

In a related development, Netskope Threat Labs reported the resurgence of a previously removed Chrome extension, “AI Sidebar with Deepseek, ChatGPT, Claude, and more,” which had engaged in data theft tactics. This extension has now introduced a monetization scheme that opens affiliate links during updates and uninstalls, further complicating the landscape of browser security.

As investigations continue, users are advised to exercise caution when installing VPN and proxy extensions, particularly those that claim to offer premium services without clear verification.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

spot_img

Related articles

Recent articles

Lazarus Group Exploits Windows Zero-Day Vulnerability to Deploy Backdoor Targeting Defense Firms Worldwide

The North Korean threat actor known as Lazarus Group has exploited a newly patched zero-day vulnerability in Microsoft Windows to deploy a previously unseen...

OpenAI Expands Daybreak Program to Include Specialized Cybersecurity Services

OpenAI has announced an expansion of its Daybreak program, which now includes specialized cybersecurity services aimed at enhancing defensive capabilities. This update, detailed in...

WhatsApp Launches Beta of Scam Alert Feature to Identify Suspicious Messages

WhatsApp has initiated a limited beta rollout of its Scam Alert feature, designed to identify suspicious messages from non-contacts using an on-device machine learning...

Ransomware Recovery Challenges: 34% of ANZ Organizations Still Opt to Pay Ransom Despite Uncertain Outcomes

Research published by Commvault reveals that 34% of organizations in Australia and New Zealand that experienced a ransomware attack opted to pay the ransom....