Hundreds of Malicious Chrome VPN Extensions Route Traffic Through Proxy

Over 737 Chrome Web Store extensions impersonated legitimate VPN services like Proton VPN, NordVPN, and Cloudflare, redirecting user traffic through SOCKS5 proxies controlled by a single provider. Downloaded nearly 75,000 times primarily by Russian users seeking to bypass blocked services, the extensions used 40 publisher accounts and a shared analytics account. Socket researchers identified that 520 extensions configured Chrome to route all traffic through operator-controlled proxies, while 104 used DNS-over-HTTPS to hide proxy hostnames.

Some extensions advertised non-existent premium servers for subscription fraud, and the campaign appears designed to funnel users to a Russian subscription-based VPN service. Indicators of deception included brand impersonation, fake server locations, nonfunctional payment mechanisms, and remote configuration changes after approval. While Google removed over 200 extensions, more than 500 remain available on the Chrome Web Store. The malicious extensions position attackers to read all browser traffic, including destinations, TLS SNI values, and HTTP requests. Users are advised to check for any of the identified extensions and remove them, then verify Chrome's proxy configuration is restored to default settings. The researchers published a full list of extension IDs for detection purposes. The campaign leveraged techniques to hide proxy destinations from analysis and mislead store reviewers. The extensions impersonated dozens of established brands to gain user trust. The campaign reflects evolving tactics to exploit VPN demand for malicious purposes.

Read more...

Read More

Got Something To Say?

Your email address will not be published.