Cybersecurity NewsArchived Aug 12, 2026✓ Full text saved
Hundreds of Chrome extensions advertised as free VPN or proxy tools have been tied to a large traffic-redirection operation. The listings promised privacy and access to blocked services, but their code sent browser sessions through SOCKS5 proxy servers controlled by the operation. The scale makes the discovery especially concerning. Researchers counted 737 extensions published through […] The post 737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies ap
Full text archived locally
✦ AI Summary· Claude Sonnet
HomeCyber Security News
737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies
By Tushar Subhra Dutta
August 12, 2026
Hundreds of Chrome extensions advertised as free VPN or proxy tools have been tied to a large traffic-redirection operation.
The listings promised privacy and access to blocked services, but their code sent browser sessions through SOCKS5 proxy servers controlled by the operation.
The scale makes the discovery especially concerning. Researchers counted 737 extensions published through at least 40 Chrome Web Store developer accounts, with more than 75,000 combined installs.
Many were aimed at Russian-speaking users looking for access to restricted sites and services.
Analysts at Socket.dev identified the campaign after examining hundreds of available extension packages and store listings.
Socket.dev said in a report shared with Cyber Security News (CSN) that they found that 274 extensions copied the names or branding of 66 established VPN and privacy services, giving victims a reason to believe the tools were legitimate.
The research does not claim the operators collected or misused every byte of routed data, but it confirms that their infrastructure occupied a position to observe browser traffic while an extension was connected.
737 Fake Chrome VPN Extensions Hijack Browser Traffic
The core behavior was direct and wide-reaching. Of 522 retrieved packages, 520 configured Chrome to use a fixed SOCKS5 server on port 1082.
Their bypass rules covered only local addresses, so visits from every browser tab were sent through the designated relay after a user selected Connect.
The popup of an extension branded “Лев VPN” names Муха VPN (Source – Socket.dev)
That design exposes destinations visited, connection metadata, and a user’s source IP address to the proxy operator. Plain HTTP requests could also expose their full contents.
The finding echoes earlier reporting on malicious VPN browser extensions that intercepted traffic while presenting a normal-looking service.
The extensions generally requested only the proxy permission, which may look limited to a casual installer. Yet the permission can control where browser traffic goes.
In 104 cases, the extensions resolved proxy hosts through encrypted DNS services, then supplied Chrome with a raw address, reducing the visibility of a normal domain lookup.
The operation also used remote configuration in 66 extensions. The code could follow web redirects, locate a new infrastructure domain, and download settings without an extension update.
Similar use of remote settings appeared in a free VPN surveillance campaign, underscoring why an approved extension can still change its risk profile later.
Victims may see a successful connection indicator and assume their browsing is protected, even when the extension has handed routing control to an unknown third party.
This gap between the promise on the store page and the actual network path is the campaign’s central danger. It also creates a useful path for profiling users who believed they were avoiding surveillance.
Impersonation, Evasion and User Protection
The proxy setting alone does not prove malicious intent, because browser-based privacy tools need a way to route traffic.
Socket.dev’s assessment instead points to the surrounding behavior: copied brands, promises of premium locations that did not resolve, misleading review statements, and functionality added after initial store approval.
The threat actor sells the browser extension as a named subscription tier from 99 roubles per month (Source – Socket.dev)
Investigators found 200 advertised premium server names across 40 domains that returned no address records. One examined extension displayed a polished connection screen but was coded to fail every connection attempt.
The campaign also contained review documents claiming that no data went to external servers, despite the proxy-routing code.
Google had removed 221 extensions when the data was collected, but 516 remained listed.
The pattern is consistent with the persistence seen in large malicious extension campaigns, where many lookalike listings and separate publisher accounts can outlast individual takedowns.
Users who installed a suspected extension should remove it, check Chrome’s proxy settings, and change credentials entered on non-HTTPS sites while it was active.
Organizations should inventory extensions with proxy access, watch for proxy-setting changes, and block the listed domains and addresses at both DNS and network egress, because encrypted DNS can bypass DNS-only controls.
Regular checks of extension permission abuse risks can help teams spot similar threats before they spread.
Indicators of compromise (IoCs):-
Type Indicator Description
Campaign scope 737 Chrome extension IDs, including 516 listed as live and 221 delisted Full extension-ID sets are enumerated in the source report’s IoC section.
Chrome extension ID aaeiefggdeljohngedhpmgidkjcdoebb Extension identified as part of the campaign.
Chrome extension ID aabaifmlfkdolhdbbhjblkeekaijfdfh Extension identified as part of the campaign.
Chrome extension ID abjgfdfbmmijjdfbohbhgdnjeipjbplj Extension identified as part of the campaign.
Chrome extension ID kcplchjjdpgehfdlggggoohdeoaikcan Extension containing an internal build manual.
Chrome extension ID ilpcglpcfdeoehcmjhkfhhgpldgfgjhj Extension marketed as Burёnka VPN.
Chrome extension ID oaidiemgjmaabehcfjfbkeifdpeniemm Extension that contained the archived prior build.
Chrome extension ID ofbdlgcpfnhcidmfmddnkkbkejjoffdf Delisted extension with a code skeleton matching other live packages.
Domain myxavpn[.]pro, app[.]myxavpn[.]pro Billing dashboard infrastructure.
Domain getmyxa[.]com, app[.]getmyxa[.]com, myxavpn[.]com, app[.]myxavpn[.]com Associated campaign infrastructure.
Domain myxavpn[.]site, myxavpn[.]online, myxavpn[.]tech, myxasafe[.]space Post-redirect infrastructure tier.
Domain atlasvpn[.]space, bezopasnet[.]space, cipherway[.]space, cloudmask[.]space, echosecure[.]space Proxy and landing infrastructure.
Domain gusentun[.]space, gusenvpn[.]online, horizonguard[.]space, internetprvpn[.]ru, ironproxy[.]space Proxy and landing infrastructure.
Domain korovkavpn[.]space, maskirovka[.]space, murvpn[.]space, myxasecure[.]space, myxavpn[.]space Proxy and landing infrastructure.
Domain neoncloak[.]space, netroutehub[.]space, nimbusshield[.]space, osavpn[.]su, pauktun[.]space Proxy and landing infrastructure.
Domain primeproxy[.]space, routekeeper[.]space, routeshield[.]space, salega[.]ru, securepulse[.]space Proxy and landing infrastructure.
Domain shershvpn[.]space, shieldtunnel[.]space, silashield[.]space, skorostvpn[.]space, skyproxy[.]space Proxy and landing infrastructure.
Domain spidervpn[.]online, stableproxy[.]space, stealthpath[.]space, sverchtun[.]store, sverchvpn[.]space Proxy and landing infrastructure.
Domain tarakanvpn[.]online, tunnelbase[.]space, turbotunnel[.]space, usachvpn[.]su, vaultvpn[.]space Proxy and landing infrastructure.
Domain vpn-myxa[.]ru, vpnfasters[.]space, vpnkomar[.]space, vpnmyha[.]shop, vpnmyxa[.]site, zenshield[.]space, zhuknet[.]online, zhukvpn[.]online Proxy and landing infrastructure.
Nameserver ns1[.]reg[.]ru, ns2[.]reg[.]ru Name servers associated with the campaign domain estate.
IP address 212[.]192[.]14[.]75 Host serving a large set of campaign domains.
IP address 158[.]160[.]228[.]178, 103[.]35[.]189[.]225, 103[.]35[.]191[.]173 Associated infrastructure addresses.
IP address 147[.]45[.]60[.]241, 147[.]45[.]60[.]252, 178[.]130[.]47[.]43, 178[.]130[.]47[.]44, 178[.]130[.]47[.]50, 178[.]130[.]47[.]129 SOCKS5 and campaign infrastructure addresses.
IP address 185[.]252[.]215[.]97, 185[.]252[.]215[.]98, 194[.]150[.]220[.]163, 45[.]89[.]110[.]227 SOCKS5 and campaign infrastructure addresses.
IP address 5[.]180[.]30[.]15, 5[.]180[.]30[.]122, 80[.]92[.]204[.]33, 80[.]92[.]204[.]47, 80[.]92[.]206[.]84 SOCKS5 and campaign infrastructure addresses.
IP address 86[.]104[.]74[.]110, 94[.]131[.]118[.]39, 94[.]131[.]118[.]237, 138[.]124[.]244[.]206, 130[.]17[.]1[.]197 SOCKS5 and campaign infrastructure addresses.
IP address 78[.]153[.]155[.]112, 81[.]90[.]31[.]73, 95[.]163[.]244[.]138 SOCKS5 and campaign infrastructure addresses.
File name vpn-bez-limita.zip Archived prior extension build embedded in a published package.
SHA-256 1dea4975f7aaba71bf7821fcf62deca470ef5e21f45c947b103ddeb836ef9b81 Hash of identical Chrome Web Store review-justification documents.
Credential myxavpn2024secret Hardcoded secret used in a weak premium-token verification routine.
REALITY public key OCLtjVdRxsou3429LRfjkDYgiAPs24TSgSeFZpChCEw Recovered from third-party subscription-output republications.
REALITY short ID d67ec5a8fc40ebea Recovered alongside the public key; not verified against a live node.
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
Tags
cyber security
cyber security news
Copy URL
Linkedin
Twitter
ReddIt
Telegram
Tushar Subhra Dutta
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
Cyber Security Guide
Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response
Latest Cyber News
Cyber Security News
Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs
Cyber Security News
13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts
Cyber Security
Nightmare-Eclipse Drops ShieldBreak Windows Defender 0-day Vulnerability
Cyber Security News
CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure
Cyber Security News
Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals
Expert Talks
Expert Talks
From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking
Expert Talks
Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage
Expert Talks
Your Incident Response Plan Has a Dependency You Never Approved
Expert Talks
Security in the AI Era Starts with First Principles
Cyber Security News
Planning Your AI Security – How will You Manage All Your Resources?