Researchers uncovered a large Chrome Web Store campaign in which 737 browser extensions posing as free VPN and proxy tools redirected user traffic through attacker-controlled SOCKS5 infrastructure. The extensions were tied to at least 40 developer accounts and had accumulated more than 75,000 installs, with many lures targeting Russian-speaking users seeking access to blocked or restricted online services. Investigators found that numerous listings impersonated legitimate VPN and privacy brands to gain trust.
The malicious extensions exposed users to surveillance by allowing operators to observe browsing destinations, connection metadata, source IP addresses, and potentially unencrypted HTTP traffic while victims believed their sessions were protected. Researchers also reported the use of encrypted DNS and remote configuration to hide or rapidly change backend infrastructure, and said some advertised premium servers or features did not function as claimed. Google had removed 221 of the identified extensions at the time of reporting, but 516 remained available, underscoring the scale and persistence of the campaign.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In early June, Palo Alto Networks reported more than 18 fraudulent VPN extensions for Chrome and other Chromium-based browsers. The disclosure predated the broader 737-extension campaign mapping later reported by Socks/Socket.dev.
Researchers said artifacts from the malicious Chrome extension campaign suggest the operator runs a subscription VPN business in Russia. Supporting details included a 12-digit tax number, exposed Windows build paths, and internal instructions indicating deliberate efforts to evade Chrome Web Store review.
At the time Socket.dev collected its data, Google had removed 221 extensions associated with the campaign. Despite those removals, 516 campaign-linked extensions were still available in the Chrome Web Store, indicating the operation remained active.
Socket.dev identified a campaign of 737 Chrome extensions across at least 40 developer accounts that marketed themselves as free VPN or proxy tools while routing browser traffic through attacker-controlled SOCKS5 proxies. The researchers reported more than 75,000 combined installs and widespread impersonation of legitimate VPN and privacy brands.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 87 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
9 references tracked. Mallory keeps watching after this page renders.
heise.de
Open sourcemkd-cirt.mk
Open sourcexakep.ru
Open sourcebleepingcomputer.com
Open sourcetrojan-killer.net
Open sourcethehackernews.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcesocket.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.