A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure.
The extensions, published across at least 40 Chrome Web Store developer accounts, racked up 75,486 installs. Of those identified, 274 have been found to impersonate 66 established VPN and privacy brands, including Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec, ExpressVPN, CyberGhost, Windscribe, TunnelBear, Cloudflare’s 1.1.1.1, and Google’s Outline, per Socket.
The censorship circumvention extensions “route the user’s entire browser session through SOCKS5 proxies operated by a single provider,” security researcher Kush Pandya said. “520 of the 522 in the bulk corpus route browser traffic through the same SOCKS5 infrastructure.”
The vast majority of the extensions have been found to route users’ entire browser sessions by setting “chrome.proxy.settings” to a fixed SOCKS5 server on port 1082, placing the threat actor in an adversary-in-the-middle (AitM) position to observe browser destinations, source IP addresses, TLS SNI values, and any request body sent over plain HTTP.
Every extension that configures a proxy also comes with a bypass list that only includes loopback addresses (i.e., the localhost or 127.0.0.1″), meaning every other browser request is funnelled through the SOCKS5 relay on port 1082 once the user connects to the purported VPN service.
As many as 221 browser add-ons have been removed from the Chrome Web Store, while the remaining 516 extensions have been listed as active. The threat actor is said to be running a subscription VPN business in Russia, based on a 12-digit taxpayer number and the fact that some of them leak their Windows build path (“C:\Users\ollob\OneDrive\Документы\1.myxa-work\08.06.26\<domain>\<product>\<product>-release.zip”).
Ideally, the functionality is no different from a legitimate VPN or proxy service. The defining aspect of this activity is its attempt to impersonate established brands as opposed to offering it under their own name. Some of the other red flags include –
“For each affected user, while the extension is connected, every request passes through a server the threat actor controls,” Pandya said. “Whether the threat actor owns those proxy servers or resells capacity from an upstream provider is not resolvable from the extension code. If it resells, a further party is in the same position.”
“What is established from the packages and from public infrastructure is the impersonation, the undisclosed proxy configuration, the non-existent premium servers, the false statements submitted to store reviewers, and the post-approval code substitution.”
Leave a Reply