Fake VPN Browser Extensions Hijack Traffic via Hidden Proxy Servers
Key Takeaways Malicious browser extensions, masquerading as legitimate VPN services, have been discovered hijacking user traffic. These extensions exploit hidden proxy servers to reroute internet...
Key Takeaways
- Malicious browser extensions, masquerading as legitimate VPN services, have been discovered hijacking user traffic.
- These extensions exploit hidden proxy servers to reroute internet connections, potentially exposing sensitive data.
- The threat impacts users across various browsers, with researchers identifying specific extension IDs and communication domains.
- No immediate fix is available for already compromised users beyond removal, but defenders can implement blocking strategies.
Cybersecurity researchers have uncovered a sophisticated scheme involving fake VPN browser extensions designed to surreptitiously hijack internet traffic. These deceptive add-ons reroute user connections through hidden proxy servers, creating a significant security risk for unsuspecting individuals and organizations.
Table Of Content
The malicious extensions operate by presenting themselves as legitimate virtual private network services. However, instead of providing secure, private browsing, they covertly manipulate network settings to funnel all outbound traffic through attacker-controlled infrastructure. This technique allows adversaries to potentially intercept data, monitor online activities, or inject malicious content.
Modus Operandi: The Hidden Proxy Mechanism
Upon installation, these fake VPN extensions demand broad permissions, often requesting access to “all URLs.” This extensive access is then leveraged to download routing instructions and configuration details from external command-and-control servers. Subsequently, the extensions establish a hidden proxy connection, rerouting the user’s internet traffic without their knowledge or consent.
Security experts emphasize a critical red flag: any single-site VPN extension that requires blanket access to every URL a user visits immediately poses an unacceptable trust risk. Such extensive permissions are unnecessary for legitimate VPN functionality and are a strong indicator of malicious intent.
Indicators of Compromise and Mitigation
Enterprise security teams are strongly advised to implement proactive blocking measures to counter this threat. This includes blacklisting known malicious extension IDs, configuration domains, and subscription hosts identified during the research. Furthermore, organizations should analyze archived network hashes against their managed endpoints to detect any existing compromises.
Defenders should also investigate any outbound connections originating from their networks directed towards suspicious domains. Specifically, researchers have identified several key indicators of compromise (IOCs) associated with this campaign. These include communication with s-extension.github.io, dtxtension.blogspot.com, t.me/liservers, api.hhos.ru, and “mainapi” (likely a subdomain or path on a malicious server).
What You Should Do
- Block Known IOCs: Immediately block the identified extension IDs, configuration domains (s-extension.github.io, dtxtension.blogspot.com, api.hhos.ru), and subscription hosts at your network perimeter.
- Review Browser Extensions: Audit all installed browser extensions across your organization’s endpoints. Remove any unfamiliar or suspicious VPN extensions, especially those requesting broad “all URLs” permissions.
- Monitor Outbound Traffic: Configure network monitoring tools to alert on outbound connections to the identified malicious domains and any other unusual traffic patterns.
- Educate Users: Inform employees about the risks of installing unverified browser extensions and the importance of scrutinizing permission requests, particularly for VPN services.
- Regularly Update & Patch: Ensure all web browsers and operating systems are kept up-to-date with the latest security patches to mitigate other potential attack vectors.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.