Hundreds of fake Chrome VPN extensions route traffic through a proxy
Researchers at Socket discovered hundreds of fake Chrome VPN extensions that impersonated well-known VPN and proxy services, routing users' traffic through SOCKS5 proxies operated by a single provider. The extensions were downloaded nearly 75,000 times, mainly by Russian …
Intelligence analysis by Llama

Fake Chrome VPN extensions impersonated well-known VPN and proxy services, routing users' traffic through SOCKS5 proxies operated by a single provider. The extensions were downloaded nearly 75,000 times, mainly by Russian users.
Imagine you're using a VPN to keep your browsing private, but instead, you're sending all your traffic to a stranger's computer. That's what happened with these fake Chrome VPN extensions. They looked like real VPNs, but they were actually sending your data to someone else's server. This is a big security risk, and users need to be careful when installing extensions.
Analysis
Fake Chrome VPN Extensions: A Threat to User Privacy and Security
The discovery of hundreds of fake Chrome VPN extensions by researchers at Socket highlights the growing threat of malicious browser extensions to user privacy and security. These extensions, which impersonated well-known VPN and proxy services, were able to route users' traffic through SOCKS5 proxies operated by a single provider. This not only compromised users' privacy but also put their security at risk.
The extensions were downloaded nearly 75,000 times, mainly by Russian users who were looking for tools to bypass blocked services in the country. The researchers identified three threat behaviors associated with the campaign: 520 extensions configured Chrome to route all browser traffic through the operator's SOCKS5 proxies on port 1082, 104 extensions resolved their proxy hostnames through Cloudflare or Google DNS-over-HTTPS to protect the operator's domain from scrutiny, and extensions that advertised non-existent premium servers in Japan, Singapore, Canada, Australia, and Turkey for subscription fraud.
The mechanism used by the extensions appears no different from that of a legitimate service, but the researchers identified several indicators of intentional deception, including impersonating well-known brands, advertising non-existent premium server locations, nonfunctional payment or connection mechanisms, misleading disclosures to store reviewers, adding remote configuration after the extension was approved, and the use of techniques to hide proxy destinations from analysis.
While Google removed more than 200 of the extensions related to the identified campaign, over 500 of them are still available in Chrome's Web Store. The researchers recommend that users check their browsers for any of these extensions and remove them if found. They should also confirm that Chrome's proxy configuration is back to normal.
This incident highlights the importance of being cautious when installing browser extensions and the need for users to regularly check their extensions for any suspicious activity.
Key points
- Hundreds of fake Chrome VPN extensions were discovered by researchers at Socket.
- These extensions impersonated well-known VPN and proxy services, routing users' traffic through SOCKS5 proxies operated by a single provider.
- The extensions were downloaded nearly 75,000 times, mainly by Russian users.
- Google removed more than 200 of the extensions related to the identified campaign, but over 500 are still available in Chrome's Web Store.
If users are aware of the risks and take steps to protect themselves, they can avoid falling victim to these fake extensions. Additionally, Google's efforts to remove the extensions and improve the security of the Chrome Web Store can help prevent similar incidents in the future.
The fact that over 500 of these extensions are still available in the Chrome Web Store suggests that the problem is more widespread than initially thought. If users are not careful, they may still fall victim to these fake extensions, compromising their privacy and security.



