Technical research identified 31 Russian-language Chrome extensions marketed as VPNs for accessing blocked services that allegedly share a common codebase and are distributed through three Google accounts linked to similar Gmail addresses. The extensions request broad permissions and retrieve remote proxy auto-configuration (PAC) files, enabling their operator to change proxied destinations and proxy exit infrastructure without releasing an extension update. One extension, Total VPN, was reportedly configured to route all browser traffic through the proxy service.
The research estimated roughly 356,000 installations as of September 18, 2026, including about 200,000 installations of RuTracker VPN. Backup domains reportedly correspond to premium Browsec VPN servers, but no attribution to Browsec or another operator has been established. Organizations should validate the published indicators independently before blocking them and review managed-browser extension inventories for the identified Russian-language VPN offerings, particularly extensions capable of remotely changing PAC configurations.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
Extension IDs, domains, and SHA-256 build hashes were automatically extracted as potential detection indicators. The content cautioned that these IOCs had not been independently verified and required validation before operational blocking or SIEM use.
Risky Plugins published research alleging that 31 Russian-language Chrome VPN extensions were distributed through three related Google accounts and could route selected browser traffic through operator-controlled proxies via remotely updated PAC files. The report characterized infrastructure overlap with Browsec VPN premium servers as an investigative lead, not an attribution.
The research estimated that the 31 Chrome extensions had approximately 356,000 total installations, including about 200,000 for RuTracker VPN. This was an installation-count snapshot rather than an independently verified compromise total.
A Risky Plugins research publication states that its authors analyzed the code and decoded remote configurations of the extensions on September 3 and 4. The analysis identified 31 extensions allegedly sharing a codebase and using remotely retrieved PAC proxy configurations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 32 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.