Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

The Great Chrome VPN Extension Scam: A Threat to Browser Security and Privacy


A massive set of 737 free Chrome VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extensions impersonate established VPN and privacy brands, posing significant security risks to users.

  • Cybersecurity researchers discovered 737 free Chrome VPN and proxy extensions targeting Russian-speaking users, with over 75,000 installs.
  • The extensions impersonate 66 established VPN brands, including Proton VPN and ExpressVPN, to route user traffic through a proxy infrastructure.
  • The extensions can intercept browser traffic, observe destination IP addresses, and steal sensitive information using "Prompt Poaching" techniques.
  • Users should be vigilant when installing browser extensions from unknown sources to avoid security risks.



  • A recent investigation by cybersecurity researchers has uncovered a massive set of 737 free Chrome VPN and proxy extensions that have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extensions, published across at least 40 Chrome Web Store developer accounts, racked up 75,486 installs. Of those identified, 274 have been found to impersonate 66 established VPN and privacy brands, including Proton VPN, NordVPN, Surfshark, AdGuard VPN, Browsec, ExpressVPN, CyberGhost, Windscribe, TunnelBear, Cloudflare's 1.1.1.1, and Google's Outline.

    The extensions in question are capable of routing users' entire browser sessions by setting "chrome.proxy.settings" to a fixed SOCKS5 server on port 1082, placing the threat actor in an adversary-in-the-middle (AitM) position to observe browser destinations, source IP addresses, TLS SNI values, and any request body sent over plain HTTP. Every extension that configures a proxy also comes with a bypass list that only includes loopback addresses, meaning every other browser request is funnelled through the SOCKS5 relay on port 1082 once the user connects to the purported VPN service.

    The threat actor is said to be running a subscription VPN business in Russia, based on a 12-digit taxpayer number and the fact that some of them leak their Windows build path ("C:\Users\ollob\OneDrive\Документы\1.myxa-work\08.06.26\\-release.zip"). Ideally, the functionality is no different from a legitimate VPN or proxy service. The defining aspect of this activity is its attempt to impersonate established brands as opposed to offering it under their own name. Some of the other red flags include advertising paid tiers (or premium locations) that do not exist, DNS-over-HTTPS blocklist evasion, failing every connection attempt while showing a complete fake interface, including a working connecting animation and status indicator, shipping an internal manual named "Промт для сотрудников" (translated to "Prompt for employees") that instructs them to avoid putting the domain directly into "chrome.proxy.settings" (and instead provide only the resolved IP) and refrain from using a domain from another extension without separate instructions.

    Presence of comments that indicate a deliberate attempt to evade Chrome Web Store policies, adding a new remote-configuration layer after extension approval, attempts to game the Chrome Web Store review process by submitting identical justifications, stating "No data transmitted to external servers" or "No user tracking or logging". For each affected user, while the extension is connected, every request passes through a server the threat actor controls.

    Researchers have also found that the extensions use a sophisticated technique called "Prompt Poaching", which involves sending fake prompts to the Google Chrome browser, allowing attackers to steal sensitive information. The clean-then-poisoned update sequence spread across versions 1.7.2.0 and 1.7.3.0 took place via Google's CRX content delivery network on July 31, 2026, pushing out a monetization scheme – a "surgical" 21-line addition – built around extension update and uninstall events.

    The investigation highlights the need for users to be vigilant when installing browser extensions from unknown sources, as these malicious extensions can pose significant security risks. It also emphasizes the importance of maintaining up-to-date software and using reputable antivirus software to protect against such threats.

    In related news, Netskope Threat Labs has highlighted the return of a Google Chrome extension named "AI Sidebar with Deepseek, ChatGPT, Claude, and more." months after it was removed for engaging in Prompt Poaching tactics. The clean-then-poisoned update sequence took place via Google's CRX content delivery network on July 31, 2026, pushing out a monetization scheme – a "surgical" 21-line addition – built around extension update and uninstall events.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/The-Great-Chrome-VPN-Extension-Scam-A-Threat-to-Browser-Security-and-Privacy-ehn.shtml

  • https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html


  • Published: Wed Aug 12 10:11:50 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us