CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◇ Industry News & Leadership Aug 12, 2026

737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies

Cybersecurity News Archived Aug 12, 2026 ✓ Full text saved

Hundreds of Chrome extensions advertised as free VPN or proxy tools have been tied to a large traffic-redirection operation. The listings promised privacy and access to blocked services, but their code sent browser sessions through SOCKS5 proxy servers controlled by the operation. The scale makes the discovery especially concerning. Researchers counted 737 extensions published through […] The post 737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies ap

Full text archived locally
✦ AI Summary · Claude Sonnet


    HomeCyber Security News 737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies By Tushar Subhra Dutta August 12, 2026 Hundreds of Chrome extensions advertised as free VPN or proxy tools have been tied to a large traffic-redirection operation. The listings promised privacy and access to blocked services, but their code sent browser sessions through SOCKS5 proxy servers controlled by the operation. The scale makes the discovery especially concerning. Researchers counted 737 extensions published through at least 40 Chrome Web Store developer accounts, with more than 75,000 combined installs. Many were aimed at Russian-speaking users looking for access to restricted sites and services. Analysts at Socket.dev identified the campaign after examining hundreds of available extension packages and store listings. Socket.dev said in a report shared with Cyber Security News (CSN) that they found that 274 extensions copied the names or branding of 66 established VPN and privacy services, giving victims a reason to believe the tools were legitimate. The research does not claim the operators collected or misused every byte of routed data, but it confirms that their infrastructure occupied a position to observe browser traffic while an extension was connected. 737 Fake Chrome VPN Extensions Hijack Browser Traffic The core behavior was direct and wide-reaching. Of 522 retrieved packages, 520 configured Chrome to use a fixed SOCKS5 server on port 1082. Their bypass rules covered only local addresses, so visits from every browser tab were sent through the designated relay after a user selected Connect. The popup of an extension branded “Лев VPN” names Муха VPN (Source – Socket.dev) That design exposes destinations visited, connection metadata, and a user’s source IP address to the proxy operator. Plain HTTP requests could also expose their full contents. The finding echoes earlier reporting on malicious VPN browser extensions that intercepted traffic while presenting a normal-looking service. The extensions generally requested only the proxy permission, which may look limited to a casual installer. Yet the permission can control where browser traffic goes. In 104 cases, the extensions resolved proxy hosts through encrypted DNS services, then supplied Chrome with a raw address, reducing the visibility of a normal domain lookup. The operation also used remote configuration in 66 extensions. The code could follow web redirects, locate a new infrastructure domain, and download settings without an extension update. Similar use of remote settings appeared in a free VPN surveillance campaign, underscoring why an approved extension can still change its risk profile later. Victims may see a successful connection indicator and assume their browsing is protected, even when the extension has handed routing control to an unknown third party. This gap between the promise on the store page and the actual network path is the campaign’s central danger. It also creates a useful path for profiling users who believed they were avoiding surveillance. Impersonation, Evasion and User Protection The proxy setting alone does not prove malicious intent, because browser-based privacy tools need a way to route traffic. Socket.dev’s assessment instead points to the surrounding behavior: copied brands, promises of premium locations that did not resolve, misleading review statements, and functionality added after initial store approval. The threat actor sells the browser extension as a named subscription tier from 99 roubles per month (Source – Socket.dev) Investigators found 200 advertised premium server names across 40 domains that returned no address records. One examined extension displayed a polished connection screen but was coded to fail every connection attempt. The campaign also contained review documents claiming that no data went to external servers, despite the proxy-routing code. Google had removed 221 extensions when the data was collected, but 516 remained listed. The pattern is consistent with the persistence seen in large malicious extension campaigns, where many lookalike listings and separate publisher accounts can outlast individual takedowns. Users who installed a suspected extension should remove it, check Chrome’s proxy settings, and change credentials entered on non-HTTPS sites while it was active. Organizations should inventory extensions with proxy access, watch for proxy-setting changes, and block the listed domains and addresses at both DNS and network egress, because encrypted DNS can bypass DNS-only controls. Regular checks of extension permission abuse risks can help teams spot similar threats before they spread. Indicators of compromise (IoCs):- Type Indicator Description Campaign scope 737 Chrome extension IDs, including 516 listed as live and 221 delisted Full extension-ID sets are enumerated in the source report’s IoC section.  Chrome extension ID aaeiefggdeljohngedhpmgidkjcdoebb Extension identified as part of the campaign. Chrome extension ID aabaifmlfkdolhdbbhjblkeekaijfdfh Extension identified as part of the campaign. Chrome extension ID abjgfdfbmmijjdfbohbhgdnjeipjbplj Extension identified as part of the campaign. Chrome extension ID kcplchjjdpgehfdlggggoohdeoaikcan Extension containing an internal build manual. Chrome extension ID ilpcglpcfdeoehcmjhkfhhgpldgfgjhj Extension marketed as Burёnka VPN. Chrome extension ID oaidiemgjmaabehcfjfbkeifdpeniemm Extension that contained the archived prior build. Chrome extension ID ofbdlgcpfnhcidmfmddnkkbkejjoffdf Delisted extension with a code skeleton matching other live packages. Domain myxavpn[.]pro, app[.]myxavpn[.]pro Billing dashboard infrastructure. Domain getmyxa[.]com, app[.]getmyxa[.]com, myxavpn[.]com, app[.]myxavpn[.]com Associated campaign infrastructure. Domain myxavpn[.]site, myxavpn[.]online, myxavpn[.]tech, myxasafe[.]space Post-redirect infrastructure tier. Domain atlasvpn[.]space, bezopasnet[.]space, cipherway[.]space, cloudmask[.]space, echosecure[.]space Proxy and landing infrastructure. Domain gusentun[.]space, gusenvpn[.]online, horizonguard[.]space, internetprvpn[.]ru, ironproxy[.]space Proxy and landing infrastructure. Domain korovkavpn[.]space, maskirovka[.]space, murvpn[.]space, myxasecure[.]space, myxavpn[.]space Proxy and landing infrastructure. Domain neoncloak[.]space, netroutehub[.]space, nimbusshield[.]space, osavpn[.]su, pauktun[.]space Proxy and landing infrastructure. Domain primeproxy[.]space, routekeeper[.]space, routeshield[.]space, salega[.]ru, securepulse[.]space Proxy and landing infrastructure. Domain shershvpn[.]space, shieldtunnel[.]space, silashield[.]space, skorostvpn[.]space, skyproxy[.]space Proxy and landing infrastructure. Domain spidervpn[.]online, stableproxy[.]space, stealthpath[.]space, sverchtun[.]store, sverchvpn[.]space Proxy and landing infrastructure. Domain tarakanvpn[.]online, tunnelbase[.]space, turbotunnel[.]space, usachvpn[.]su, vaultvpn[.]space Proxy and landing infrastructure. Domain vpn-myxa[.]ru, vpnfasters[.]space, vpnkomar[.]space, vpnmyha[.]shop, vpnmyxa[.]site, zenshield[.]space, zhuknet[.]online, zhukvpn[.]online Proxy and landing infrastructure. Nameserver ns1[.]reg[.]ru, ns2[.]reg[.]ru Name servers associated with the campaign domain estate. IP address 212[.]192[.]14[.]75 Host serving a large set of campaign domains. IP address 158[.]160[.]228[.]178, 103[.]35[.]189[.]225, 103[.]35[.]191[.]173 Associated infrastructure addresses. IP address 147[.]45[.]60[.]241, 147[.]45[.]60[.]252, 178[.]130[.]47[.]43, 178[.]130[.]47[.]44, 178[.]130[.]47[.]50, 178[.]130[.]47[.]129 SOCKS5 and campaign infrastructure addresses. IP address 185[.]252[.]215[.]97, 185[.]252[.]215[.]98, 194[.]150[.]220[.]163, 45[.]89[.]110[.]227 SOCKS5 and campaign infrastructure addresses. IP address 5[.]180[.]30[.]15, 5[.]180[.]30[.]122, 80[.]92[.]204[.]33, 80[.]92[.]204[.]47, 80[.]92[.]206[.]84 SOCKS5 and campaign infrastructure addresses. IP address 86[.]104[.]74[.]110, 94[.]131[.]118[.]39, 94[.]131[.]118[.]237, 138[.]124[.]244[.]206, 130[.]17[.]1[.]197 SOCKS5 and campaign infrastructure addresses. IP address 78[.]153[.]155[.]112, 81[.]90[.]31[.]73, 95[.]163[.]244[.]138 SOCKS5 and campaign infrastructure addresses. File name vpn-bez-limita.zip Archived prior extension build embedded in a published package. SHA-256 1dea4975f7aaba71bf7821fcf62deca470ef5e21f45c947b103ddeb836ef9b81 Hash of identical Chrome Web Store review-justification documents. Credential myxavpn2024secret Hardcoded secret used in a weak premium-token verification routine. REALITY public key OCLtjVdRxsou3429LRfjkDYgiAPs24TSgSeFZpChCEw Recovered from third-party subscription-output republications. REALITY short ID d67ec5a8fc40ebea Recovered alongside the public key; not verified against a live node.  Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM. Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world Tags cyber security cyber security news Copy URL Linkedin Twitter ReddIt Telegram Tushar Subhra Dutta Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics. Cyber Security Guide Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways  Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026) An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response  Latest Cyber News Cyber Security News Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs Cyber Security News 13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts Cyber Security Nightmare-Eclipse Drops ShieldBreak Windows Defender 0-day Vulnerability Cyber Security News CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure Cyber Security News Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals Expert Talks Expert Talks From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking  Expert Talks Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage  Expert Talks Your Incident Response Plan Has a Dependency You Never Approved Expert Talks Security in the AI Era Starts with First Principles  Cyber Security News Planning Your AI Security – How will You Manage All Your Resources?
    💬 Team Notes
    Article Info
    Source
    Cybersecurity News
    Category
    ◇ Industry News & Leadership
    Published
    Aug 12, 2026
    Archived
    Aug 12, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗