Hundreds of Chrome extensions advertised as free VPN or proxy tools have been tied to a large traffic-redirection operation.
The listings promised privacy and access to blocked services, but their code sent browser sessions through SOCKS5 proxy servers controlled by the operation.
The scale makes the discovery especially concerning. Researchers counted 737 extensions published through at least 40 Chrome Web Store developer accounts, with more than 75,000 combined installs.
Many were aimed at Russian-speaking users looking for access to restricted sites and services.
Analysts at Socket.dev identified the campaign after examining hundreds of available extension packages and store listings.
Socket.dev said in a report shared with Cyber Security News (CSN) that they found that 274 extensions copied the names or branding of 66 established VPN and privacy services, giving victims a reason to believe the tools were legitimate.
The research does not claim the operators collected or misused every byte of routed data, but it confirms that their infrastructure occupied a position to observe browser traffic while an extension was connected.
737 Fake Chrome VPN Extensions Hijack Browser Traffic
The core behavior was direct and wide-reaching. Of 522 retrieved packages, 520 configured Chrome to use a fixed SOCKS5 server on port 1082.
Their bypass rules covered only local addresses, so visits from every browser tab were sent through the designated relay after a user selected Connect.
That design exposes destinations visited, connection metadata, and a user’s source IP address to the proxy operator. Plain HTTP requests could also expose their full contents.
The finding echoes earlier reporting on malicious VPN browser extensions that intercepted traffic while presenting a normal-looking service.
The extensions generally requested only the proxy permission, which may look limited to a casual installer. Yet the permission can control where browser traffic goes.
In 104 cases, the extensions resolved proxy hosts through encrypted DNS services, then supplied Chrome with a raw address, reducing the visibility of a normal domain lookup.
The operation also used remote configuration in 66 extensions. The code could follow web redirects, locate a new infrastructure domain, and download settings without an extension update.
Similar use of remote settings appeared in a free VPN surveillance campaign, underscoring why an approved extension can still change its risk profile later.
Victims may see a successful connection indicator and assume their browsing is protected, even when the extension has handed routing control to an unknown third party.
This gap between the promise on the store page and the actual network path is the campaign’s central danger. It also creates a useful path for profiling users who believed they were avoiding surveillance.
Impersonation, Evasion and User Protection
The proxy setting alone does not prove malicious intent, because browser-based privacy tools need a way to route traffic.
Socket.dev’s assessment instead points to the surrounding behavior: copied brands, promises of premium locations that did not resolve, misleading review statements, and functionality added after initial store approval.
.webp)
Investigators found 200 advertised premium server names across 40 domains that returned no address records. One examined extension displayed a polished connection screen but was coded to fail every connection attempt.
The campaign also contained review documents claiming that no data went to external servers, despite the proxy-routing code.
Google had removed 221 extensions when the data was collected, but 516 remained listed.
The pattern is consistent with the persistence seen in large malicious extension campaigns, where many lookalike listings and separate publisher accounts can outlast individual takedowns.
Users who installed a suspected extension should remove it, check Chrome’s proxy settings, and change credentials entered on non-HTTPS sites while it was active.
Organizations should inventory extensions with proxy access, watch for proxy-setting changes, and block the listed domains and addresses at both DNS and network egress, because encrypted DNS can bypass DNS-only controls.
Regular checks of extension permission abuse risks can help teams spot similar threats before they spread.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Campaign scope | 737 Chrome extension IDs, including 516 listed as live and 221 delisted | Full extension-ID sets are enumerated in the source report’s IoC section. |
| Chrome extension ID | aaeiefggdeljohngedhpmgidkjcdoebb | Extension identified as part of the campaign. |
| Chrome extension ID | aabaifmlfkdolhdbbhjblkeekaijfdfh | Extension identified as part of the campaign. |
| Chrome extension ID | abjgfdfbmmijjdfbohbhgdnjeipjbplj | Extension identified as part of the campaign. |
| Chrome extension ID | kcplchjjdpgehfdlggggoohdeoaikcan | Extension containing an internal build manual. |
| Chrome extension ID | ilpcglpcfdeoehcmjhkfhhgpldgfgjhj | Extension marketed as Burёnka VPN. |
| Chrome extension ID | oaidiemgjmaabehcfjfbkeifdpeniemm | Extension that contained the archived prior build. |
| Chrome extension ID | ofbdlgcpfnhcidmfmddnkkbkejjoffdf | Delisted extension with a code skeleton matching other live packages. |
| Domain | myxavpn[.]pro, app[.]myxavpn[.]pro | Billing dashboard infrastructure. |
| Domain | getmyxa[.]com, app[.]getmyxa[.]com, myxavpn[.]com, app[.]myxavpn[.]com | Associated campaign infrastructure. |
| Domain | myxavpn[.]site, myxavpn[.]online, myxavpn[.]tech, myxasafe[.]space | Post-redirect infrastructure tier. |
| Domain | atlasvpn[.]space, bezopasnet[.]space, cipherway[.]space, cloudmask[.]space, echosecure[.]space | Proxy and landing infrastructure. |
| Domain | gusentun[.]space, gusenvpn[.]online, horizonguard[.]space, internetprvpn[.]ru, ironproxy[.]space | Proxy and landing infrastructure. |
| Domain | korovkavpn[.]space, maskirovka[.]space, murvpn[.]space, myxasecure[.]space, myxavpn[.]space | Proxy and landing infrastructure. |
| Domain | neoncloak[.]space, netroutehub[.]space, nimbusshield[.]space, osavpn[.]su, pauktun[.]space | Proxy and landing infrastructure. |
| Domain | primeproxy[.]space, routekeeper[.]space, routeshield[.]space, salega[.]ru, securepulse[.]space | Proxy and landing infrastructure. |
| Domain | shershvpn[.]space, shieldtunnel[.]space, silashield[.]space, skorostvpn[.]space, skyproxy[.]space | Proxy and landing infrastructure. |
| Domain | spidervpn[.]online, stableproxy[.]space, stealthpath[.]space, sverchtun[.]store, sverchvpn[.]space | Proxy and landing infrastructure. |
| Domain | tarakanvpn[.]online, tunnelbase[.]space, turbotunnel[.]space, usachvpn[.]su, vaultvpn[.]space | Proxy and landing infrastructure. |
| Domain | vpn-myxa[.]ru, vpnfasters[.]space, vpnkomar[.]space, vpnmyha[.]shop, vpnmyxa[.]site, zenshield[.]space, zhuknet[.]online, zhukvpn[.]online | Proxy and landing infrastructure. |
| Nameserver | ns1[.]reg[.]ru, ns2[.]reg[.]ru | Name servers associated with the campaign domain estate. |
| IP address | 212[.]192[.]14[.]75 | Host serving a large set of campaign domains. |
| IP address | 158[.]160[.]228[.]178, 103[.]35[.]189[.]225, 103[.]35[.]191[.]173 | Associated infrastructure addresses. |
| IP address | 147[.]45[.]60[.]241, 147[.]45[.]60[.]252, 178[.]130[.]47[.]43, 178[.]130[.]47[.]44, 178[.]130[.]47[.]50, 178[.]130[.]47[.]129 | SOCKS5 and campaign infrastructure addresses. |
| IP address | 185[.]252[.]215[.]97, 185[.]252[.]215[.]98, 194[.]150[.]220[.]163, 45[.]89[.]110[.]227 | SOCKS5 and campaign infrastructure addresses. |
| IP address | 5[.]180[.]30[.]15, 5[.]180[.]30[.]122, 80[.]92[.]204[.]33, 80[.]92[.]204[.]47, 80[.]92[.]206[.]84 | SOCKS5 and campaign infrastructure addresses. |
| IP address | 86[.]104[.]74[.]110, 94[.]131[.]118[.]39, 94[.]131[.]118[.]237, 138[.]124[.]244[.]206, 130[.]17[.]1[.]197 | SOCKS5 and campaign infrastructure addresses. |
| IP address | 78[.]153[.]155[.]112, 81[.]90[.]31[.]73, 95[.]163[.]244[.]138 | SOCKS5 and campaign infrastructure addresses. |
| File name | vpn-bez-limita.zip | Archived prior extension build embedded in a published package. |
| SHA-256 | 1dea4975f7aaba71bf7821fcf62deca470ef5e21f45c947b103ddeb836ef9b81 | Hash of identical Chrome Web Store review-justification documents. |
| Credential | myxavpn2024secret | Hardcoded secret used in a weak premium-token verification routine. |
| REALITY public key | OCLtjVdRxsou3429LRfjkDYgiAPs24TSgSeFZpChCEw | Recovered from third-party subscription-output republications. |
| REALITY short ID | d67ec5a8fc40ebea | Recovered alongside the public key; not verified against a live node. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

