CyberSecurityNews

737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies


Hundreds of Chrome extensions advertised as free VPN or proxy tools have been tied to a large traffic-redirection operation.

The listings promised privacy and access to blocked services, but their code sent browser sessions through SOCKS5 proxy servers controlled by the operation.

The scale makes the discovery especially concerning. Researchers counted 737 extensions published through at least 40 Chrome Web Store developer accounts, with more than 75,000 combined installs.

Many were aimed at Russian-speaking users looking for access to restricted sites and services.

Analysts at Socket.dev identified the campaign after examining hundreds of available extension packages and store listings.

Socket.dev said in a report shared with Cyber Security News (CSN) that they found that 274 extensions copied the names or branding of 66 established VPN and privacy services, giving victims a reason to believe the tools were legitimate.

The research does not claim the operators collected or misused every byte of routed data, but it confirms that their infrastructure occupied a position to observe browser traffic while an extension was connected.

737 Fake Chrome VPN Extensions Hijack Browser Traffic

The core behavior was direct and wide-reaching. Of 522 retrieved packages, 520 configured Chrome to use a fixed SOCKS5 server on port 1082.

Their bypass rules covered only local addresses, so visits from every browser tab were sent through the designated relay after a user selected Connect.

The popup of an extension branded “Лев VPN” names Муха VPN (Source – Socket.dev)

That design exposes destinations visited, connection metadata, and a user’s source IP address to the proxy operator. Plain HTTP requests could also expose their full contents.

The finding echoes earlier reporting on malicious VPN browser extensions that intercepted traffic while presenting a normal-looking service.

The extensions generally requested only the proxy permission, which may look limited to a casual installer. Yet the permission can control where browser traffic goes.

In 104 cases, the extensions resolved proxy hosts through encrypted DNS services, then supplied Chrome with a raw address, reducing the visibility of a normal domain lookup.

The operation also used remote configuration in 66 extensions. The code could follow web redirects, locate a new infrastructure domain, and download settings without an extension update.

Similar use of remote settings appeared in a free VPN surveillance campaign, underscoring why an approved extension can still change its risk profile later.

Victims may see a successful connection indicator and assume their browsing is protected, even when the extension has handed routing control to an unknown third party.

This gap between the promise on the store page and the actual network path is the campaign’s central danger. It also creates a useful path for profiling users who believed they were avoiding surveillance.

Impersonation, Evasion and User Protection

The proxy setting alone does not prove malicious intent, because browser-based privacy tools need a way to route traffic.

Socket.dev’s assessment instead points to the surrounding behavior: copied brands, promises of premium locations that did not resolve, misleading review statements, and functionality added after initial store approval.

The threat actor sells the browser extension as a named subscription tier from 99 roubles per month (Source - Socket.dev)
The threat actor sells the browser extension as a named subscription tier from 99 roubles per month (Source – Socket.dev)

Investigators found 200 advertised premium server names across 40 domains that returned no address records. One examined extension displayed a polished connection screen but was coded to fail every connection attempt.

The campaign also contained review documents claiming that no data went to external servers, despite the proxy-routing code.

Google had removed 221 extensions when the data was collected, but 516 remained listed.

The pattern is consistent with the persistence seen in large malicious extension campaigns, where many lookalike listings and separate publisher accounts can outlast individual takedowns.

Users who installed a suspected extension should remove it, check Chrome’s proxy settings, and change credentials entered on non-HTTPS sites while it was active.

Organizations should inventory extensions with proxy access, watch for proxy-setting changes, and block the listed domains and addresses at both DNS and network egress, because encrypted DNS can bypass DNS-only controls.

Regular checks of extension permission abuse risks can help teams spot similar threats before they spread.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Campaign scope737 Chrome extension IDs, including 516 listed as live and 221 delistedFull extension-ID sets are enumerated in the source report’s IoC section. 
Chrome extension IDaaeiefggdeljohngedhpmgidkjcdoebbExtension identified as part of the campaign.
Chrome extension IDaabaifmlfkdolhdbbhjblkeekaijfdfhExtension identified as part of the campaign.
Chrome extension IDabjgfdfbmmijjdfbohbhgdnjeipjbpljExtension identified as part of the campaign.
Chrome extension IDkcplchjjdpgehfdlggggoohdeoaikcanExtension containing an internal build manual.
Chrome extension IDilpcglpcfdeoehcmjhkfhhgpldgfgjhjExtension marketed as Burёnka VPN.
Chrome extension IDoaidiemgjmaabehcfjfbkeifdpeniemmExtension that contained the archived prior build.
Chrome extension IDofbdlgcpfnhcidmfmddnkkbkejjoffdfDelisted extension with a code skeleton matching other live packages.
Domainmyxavpn[.]proapp[.]myxavpn[.]proBilling dashboard infrastructure.
Domaingetmyxa[.]comapp[.]getmyxa[.]commyxavpn[.]comapp[.]myxavpn[.]comAssociated campaign infrastructure.
Domainmyxavpn[.]sitemyxavpn[.]onlinemyxavpn[.]techmyxasafe[.]spacePost-redirect infrastructure tier.
Domainatlasvpn[.]spacebezopasnet[.]spacecipherway[.]spacecloudmask[.]spaceechosecure[.]spaceProxy and landing infrastructure.
Domaingusentun[.]spacegusenvpn[.]onlinehorizonguard[.]spaceinternetprvpn[.]ruironproxy[.]spaceProxy and landing infrastructure.
Domainkorovkavpn[.]spacemaskirovka[.]spacemurvpn[.]spacemyxasecure[.]spacemyxavpn[.]spaceProxy and landing infrastructure.
Domainneoncloak[.]spacenetroutehub[.]spacenimbusshield[.]spaceosavpn[.]supauktun[.]spaceProxy and landing infrastructure.
Domainprimeproxy[.]spaceroutekeeper[.]spacerouteshield[.]spacesalega[.]rusecurepulse[.]spaceProxy and landing infrastructure.
Domainshershvpn[.]spaceshieldtunnel[.]spacesilashield[.]spaceskorostvpn[.]spaceskyproxy[.]spaceProxy and landing infrastructure.
Domainspidervpn[.]onlinestableproxy[.]spacestealthpath[.]spacesverchtun[.]storesverchvpn[.]spaceProxy and landing infrastructure.
Domaintarakanvpn[.]onlinetunnelbase[.]spaceturbotunnel[.]spaceusachvpn[.]suvaultvpn[.]spaceProxy and landing infrastructure.
Domainvpn-myxa[.]ruvpnfasters[.]spacevpnkomar[.]spacevpnmyha[.]shopvpnmyxa[.]sitezenshield[.]spacezhuknet[.]onlinezhukvpn[.]onlineProxy and landing infrastructure.
Nameserverns1[.]reg[.]runs2[.]reg[.]ruName servers associated with the campaign domain estate.
IP address212[.]192[.]14[.]75Host serving a large set of campaign domains.
IP address158[.]160[.]228[.]178103[.]35[.]189[.]225103[.]35[.]191[.]173Associated infrastructure addresses.
IP address147[.]45[.]60[.]241147[.]45[.]60[.]252178[.]130[.]47[.]43178[.]130[.]47[.]44178[.]130[.]47[.]50178[.]130[.]47[.]129SOCKS5 and campaign infrastructure addresses.
IP address185[.]252[.]215[.]97185[.]252[.]215[.]98194[.]150[.]220[.]16345[.]89[.]110[.]227SOCKS5 and campaign infrastructure addresses.
IP address5[.]180[.]30[.]155[.]180[.]30[.]12280[.]92[.]204[.]3380[.]92[.]204[.]4780[.]92[.]206[.]84SOCKS5 and campaign infrastructure addresses.
IP address86[.]104[.]74[.]11094[.]131[.]118[.]3994[.]131[.]118[.]237138[.]124[.]244[.]206130[.]17[.]1[.]197SOCKS5 and campaign infrastructure addresses.
IP address78[.]153[.]155[.]11281[.]90[.]31[.]7395[.]163[.]244[.]138SOCKS5 and campaign infrastructure addresses.
File namevpn-bez-limita.zipArchived prior extension build embedded in a published package.
SHA-2561dea4975f7aaba71bf7821fcf62deca470ef5e21f45c947b103ddeb836ef9b81Hash of identical Chrome Web Store review-justification documents.
Credentialmyxavpn2024secretHardcoded secret used in a weak premium-token verification routine.
REALITY public keyOCLtjVdRxsou3429LRfjkDYgiAPs24TSgSeFZpChCEwRecovered from third-party subscription-output republications.
REALITY short IDd67ec5a8fc40ebeaRecovered alongside the public key; not verified against a live node. 

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world



Source link