Hundreds of fake VPN Chrome extensions route traffic through proxies

Hundreds of fake VPN Chrome extensions route traffic through proxies

More than 737 browser extensions published on the Chrome Web Store mimicked well-known VPN and proxy services while routing users’ traffic through SOCKS5 proxies operated by a single vendor.

Some of the extensions mimicked dozens of established brands, including Proton VPN, NordVPN, Surfshark, ExpressVPN, and Cloudflare’s Public Domain Name System (DNS) resolver 1.1.1.1.

Researchers from the application security company Socket found that the campaign relied on 40 publisher accounts and used a shared account for analysis.

image

While on the Chrome Web Store, the extensions were downloaded nearly 75,000 times, mainly by Russian users looking for tools to bypass blocked services in the country.

“With all browser traffic forced through it (the relay), the threat actor’s server is positioned to read every destination, every TLS SNI value, the victim’s source IP, and every request body sent over plain HTTP,” Socket explains.

The researchers identified three threatening behaviors associated with the campaign:

  • 520 extensions configured Chrome to route all browser traffic through the carrier’s SOCKS5 proxy on port 1082.
  • 104 extensions resolved their proxy hostnames via Cloudflare or Google DNS-over-HTTPS to protect the operator’s domain from inspection.
  • Extensions that advertise non-existent premium servers in Japan, Singapore, Canada, Australia and Turkey for subscription scams

Socket was unable to analyze the code in all extensions because 212 of them had already been removed when the researchers collected them.

Based on the strings found, the campaign appears to be an attempt to drive customers to a subscription-based VPN service in Russia.

The researchers noted that the mechanism used by the extensions did not seem to differ from that of a legitimate service, but they identified several indicators of deliberate fraud:

  • impersonating famous brands
  • advertising non-existent premium server locations
  • non-functioning payment or connection mechanisms
  • misleading disclosures by store reviewers
  • adding remote configuration after extension approval
  • the use of techniques to hide proxy destinations from analysis

Socket says that although Google has removed more than 200 of the extensions associated with the identified campaign, more than 500 of them are still available in the Chrome Web Store.

Socket publishes the IDs of all extensions associated with the campaign and recommends that users check their browsers for any and remove them if found. They should also confirm that Chrome’s proxy configuration is back to normal.


article image

Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.

The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *