Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Google Chrome 115 Patches Five High-Severity Use-After-Free Flaws
August 12, 2026
Eclipse Ransomware Launches RaaS, Targets Windows, Linux, ESXi
August 12, 2026
WhatsApp launches new scam alert feature to combat social engineering
August 12, 2026
Home/Threats/Fake Chrome VPN Extensions Hijack Traffic via SOCKS5 Proxies
Threats

Fake Chrome VPN Extensions Hijack Traffic via SOCKS5 Proxies

Key Takeaways Hundreds of malicious Chrome extensions, masquerading as VPN or proxy services, have been found hijacking user traffic. These extensions redirect browser activity through...

Marcus Rodriguez
Marcus Rodriguez
August 12, 2026 5 Min Read
3 0

Key Takeaways

  • Hundreds of malicious Chrome extensions, masquerading as VPN or proxy services, have been found hijacking user traffic.
  • These extensions redirect browser activity through attacker-controlled SOCKS5 proxy servers, potentially exposing sensitive user data.
  • The campaign involved 737 extensions from at least 40 developer accounts, accumulating over 75,000 installs, many targeting Russian-speaking users.
  • Attackers leveraged brand impersonation and remote configuration capabilities to maintain persistence and evade detection.
  • Users are advised to remove suspicious extensions, verify Chrome’s proxy settings, and change credentials used on non-HTTPS sites while affected.

A sophisticated operation has been uncovered, involving hundreds of malicious Chrome extensions that pose as legitimate VPN or proxy tools. These extensions, while promising enhanced privacy and access to restricted content, surreptitiously route users’ browser traffic through SOCKS5 proxy servers under the control of the attackers. This large-scale traffic redirection poses significant privacy and security risks to affected users.

Table Of Content

  • Key Takeaways
  • The Mechanics of Traffic Hijacking
  • Impersonation, Evasion, and User Protection
  • What You Should Do

The sheer scope of this campaign is alarming. Researchers have identified 737 distinct extensions, distributed across at least 40 different Chrome Web Store developer accounts. Collectively, these extensions garnered over 75,000 installations. A significant portion of these malicious extensions specifically targeted Russian-speaking users seeking to circumvent online restrictions, as detailed in a comprehensive report.

The Mechanics of Traffic Hijacking

Analysts at Socket.dev said in a report, which was also shared with Cyber Security News (CSN), were instrumental in uncovering this campaign. Their analysis of numerous extension packages and store listings revealed the deceptive nature of these tools. A striking 274 of the identified extensions mimicked the names or branding of 66 reputable VPN and privacy services, deliberately misleading users into believing they were installing legitimate software.

While the research does not definitively state that the operators actively collected or misused all routed data, it unequivocally confirms that their infrastructure was positioned to observe browser traffic whenever an infected extension was active. This capability alone represents a severe compromise of user privacy.

The core functionality of these extensions was straightforward yet effective. Out of 522 examined packages, 520 were configured to direct Chrome’s traffic through a specific SOCKS5 server operating on port 1082. Crucially, their bypass rules were limited to local addresses, meaning that all browser activity from every open tab was routed through the attacker-controlled proxy once a user activated the “Connect” function. This setup exposes visited websites, connection metadata, and the user’s original IP address to the proxy operator. Furthermore, unencrypted HTTP requests could reveal their entire content, echoing previous reports of malicious VPN browser extensions designed to intercept traffic while appearing benign.

These extensions typically requested only the “proxy” permission, which might appear innocuous to an average user. However, this permission grants the extension complete control over how browser traffic is routed. In 104 instances, the extensions further obfuscated their activities by resolving proxy hosts via encrypted DNS services before supplying Chrome with a direct IP address. This technique effectively bypasses standard domain lookups, reducing the visibility of their malicious infrastructure.

The attackers also incorporated remote configuration capabilities into 66 of these extensions. This allowed the code to follow web redirects, identify new infrastructure domains, and download updated settings without requiring a new extension update. Such a tactic is a common feature in surveillance campaigns involving free VPNs, highlighting how an initially approved extension can evolve into a significant security risk over time.

Users, observing a successful connection indicator, would naturally assume their browsing was secure, unaware that control of their network traffic had been ceded to an unknown third party. This fundamental discrepancy between the advertised service and the actual network behavior constitutes the primary threat of this campaign, enabling the profiling of users who sought anonymity.

Impersonation, Evasion, and User Protection

The mere presence of a proxy setting in an extension does not inherently denote malicious intent, as many legitimate privacy tools rely on such routing mechanisms. However, Socket.dev’s comprehensive analysis highlighted a pattern of deceptive practices that confirmed the malicious nature of these extensions. This included the blatant copying of established brands, false promises of premium server locations that never resolved, misleading review statements, and the addition of harmful functionality after initial approval in the Chrome Web Store.

Investigators discovered 200 advertised “premium” server names across 40 different domains that consistently failed to resolve any address records. One particular extension, despite presenting a sophisticated connection interface, was coded to fail every connection attempt. The campaign also featured fabricated review documents falsely claiming that no user data was transmitted to external servers, directly contradicting the proxy-routing code.

At the time of data collection, Google had removed 221 of these malicious extensions, but a substantial 516 remained active in the Chrome Web Store. This persistence is characteristic of large-scale malicious extension campaigns, where a multitude of lookalike listings and separate publisher accounts can often outlast individual takedowns.

What You Should Do

  • Remove Suspicious Extensions: Immediately uninstall any VPN or proxy extensions that you suspect might be part of this campaign or exhibit unusual behavior. Refer to the Indicators of Compromise (IoCs) for a list of identified extensions and related infrastructure.
  • Verify Chrome Proxy Settings: After removing any questionable extensions, manually check your Chrome browser’s proxy settings to ensure they haven’t been altered. Navigate to Settings -> System -> Open your computer’s proxy settings and confirm no unauthorized proxy is configured.
  • Change Compromised Credentials: If you used the affected extensions and visited non-HTTPS websites, assume any credentials entered during that period might be compromised. Change passwords for all affected accounts.
  • Organizations:
    • Inventory Extensions: Conduct a comprehensive audit of all Chrome extensions installed across your organization, paying close attention to those with proxy access.
    • Monitor Proxy Changes: Implement monitoring for unauthorized changes to proxy settings on endpoints.
    • Block Malicious Infrastructure: Block the listed domains and IP addresses (provided in the IoCs table) at both the DNS and network egress levels. Be aware that encrypted DNS can bypass DNS-only controls.
    • Regular Permission Audits: Routinely review extension permission abuse risks to proactively identify and mitigate similar threats before they can propagate within your network.
  • Indicators of Compromise (IoCs):

    Type Indicator Description
    Campaign scope 737 Chrome extension IDs, including 516 listed as live and 221 delisted Full extension-ID sets are enumerated in the source report’s IoC section. <a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/1270eea7-8e90-44c1-a9c4-d33063ce7b99/737-Fake-Chrome-VPN-Extensions-Hijack-Browser-Traffic-Through-Attacker-Controlled-SOCKS5-Proxies.pdf?AWSAccessKeyId=ASIA2F3EMEYE6J6NT5T2&Signature=7pnl%2F5kcFJPB4W2oRQ1Wk9ue85g%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEAUaCXVzLWVhc3QtMSJHMEUCIAUTGBaSYkjonD94plnkXq23GKd0OaWVfZWnzZhBNIsBAiEAgFhIjfe1qYIYiB%2BD9TXWnqDTONNv2VDzC5Yb0THVHfAq%2FAQIzv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDPxCbmsurU6iAiwnMSrQBOnbPRYRGX6%2FnXcyIVGaD1wi0IX2Umq5Ch0vG3pnoqEhtnyUnnMS0obUfH4JQHYwy18Hi4mOJD89jGYD9mPX2YQeqOKCd%2B3JNw6KwLGELmcgRPKIbJiXOQX5klo3jg6gKtRVwdyrzH4d5VSkOPVCVcFIBi5nQwI87p%2Bm74uazx7

    Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

    Tags:

    SecurityThreat

    Share Article

    Marcus Rodriguez

    Marcus Rodriguez

    Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

    Previous Post

    WindRelay Malware Uses SpyNote RAT, NFC Relay to Drain Accounts

    Next Post

    2.86 Billion Credentials Compromised, Enterprise Access for Sale

    No Comment! Be the first one.

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    Popular Posts
    Fake Chrome VPN Extensions Hijack Traffic via SOCKS5 Proxies
    August 12, 2026
    WindRelay Malware Uses SpyNote RAT, NFC Relay to Drain Accounts
    August 12, 2026
    Fake CCleaner Downloads Deliver GhostDesk Spyware to Windows PCs
    August 12, 2026
    Top Authors
    Marcus Rodriguez
    Marcus Rodriguez
    Emy Elsamnoudy
    Emy Elsamnoudy
    Jennifer sherman
    Jennifer sherman
    Let's Connect
    156k
    2.25m
    285k

    Related Posts

    Jennifer sherman
    By Jennifer sherman
    Threats

    GlassWorm Attacks macOS via Malicious VS Code…

    January 1, 2026
    Emy Elsamnoudy
    By Emy Elsamnoudy
    Attacks

    ClickFix Attack Hides Malicious Code via Stegan Security

    January 1, 2026
    Sarah simpson
    By Sarah simpson
    Vulnerabilities

    MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

    January 1, 2026
    Emy Elsamnoudy
    By Emy Elsamnoudy
    Breaches

    Conti Ransomware Gang Leaders & Infrastructure Exposed

    January 1, 2026
    Hackers News Hackers News
    • [email protected]

    Quick Links

    • Contact Us
    • Privacy Policy
    • Terms of service

    Categories

    Attacks
    Breaches
    Comparisons
    CyberSecurity News
    Threats
    Vulnerabilities

    Let's keep in touch

    receive fresh updates and breaking cyber news every day and week!

    All Rights Reserved by HackersRadar ©2026

    Follow Us