Skip to main content

737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

0
Medium
Published: 08/12/2026 (08/12/2026, 06:52:44 UTC)
Source: AlienVault OTX General

Description

Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 09:33:53 UTC

Technical Analysis

Socket's Threat Research Team discovered a coordinated campaign of 737 malicious Chrome VPN and proxy extensions distributed across 40 developer accounts. These extensions impersonate 66 established VPN brands, including Proton VPN, NordVPN, and AmneziaVPN, accumulating over 75,000 installs. They route all browser traffic through SOCKS5 proxies on port 1082 controlled by a single operator, placing the attacker in an adversary-in-the-middle position. Premium tiers advertise non-functional servers in five countries. The campaign employs DNS-over-HTTPS for evasion, substitutes malicious code after extension approval, and manipulates Chrome Web Store reviews to appear legitimate. The operation is linked to a Russian subscription VPN business with a tax-registered individual as the contracting party.

Potential Impact

Users installing these malicious extensions risk having all their browser traffic intercepted and redirected through attacker-controlled proxies, enabling potential data interception and manipulation. Brand impersonation may lead to user trust and increased installation rates. The use of evasion techniques complicates detection and removal. Premium features advertised are non-functional, indicating fraud. The campaign targets Russian-speaking users seeking to bypass regional restrictions.

Defensive Guidance

No official patch or remediation is applicable as this is a malicious campaign involving third-party Chrome extensions. Users should avoid installing VPN or proxy extensions from unverified sources and verify the legitimacy of extensions by checking developer accounts and user reviews carefully. Security teams should monitor for and block these malicious extensions where possible. Google Chrome Web Store users should report suspicious extensions to Google for removal. Vendors and platform operators should continue to improve detection and review processes to prevent similar campaigns.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://socket.dev/blog/chrome-vpn-extension-impersonation"]
Pulse Id
6a7c183cfe509b035144c5a6

Indicators of Compromise

Ip

ValueDescriptionCopy
ip185.252.215.98
—
ip80.92.204.33
—
ip94.131.118.237
—
ip80.92.204.47
—
ip86.104.74.110
—
ip94.131.118.39
—
ip178.130.47.44
—
ip178.130.47.129
—
ip103.35.191.173
—
ip194.150.220.163
—
ip147.45.60.241
—
ip103.35.189.225
—
ip5.180.30.122
—
ip45.89.110.227
—
ip80.92.206.84
—
ip185.252.215.97
—
ip5.180.30.15
—
ip212.192.14.75
—
ip130.17.1.19
—
ip138.124.244.206
—
ip78.153.155.112
—
ip81.90.31.73
—

Domain

ValueDescriptionCopy
domainvpn-myxa.ru
—
domainsverchtun.store
—
domainmyxavpn.site
—
domainvaultvpn.space
—
domainsilashield.space
—
domainshieldtunnel.space
—
domainturbotunnel.space
—
domainechosecure.space
—
domainbezopasnet.space
—
domainzenshield.space
—
domainskyproxy.space
—
domainroutekeeper.space
—
domainstealthpath.space
—
domainsecurepulse.space
—
domainironproxy.space
—
domainprimeproxy.space
—
domainmaskirovka.space
—
domainskorostvpn.space
—
domaincloudmask.space
—
domainsverchvpn.space
—
domainnimbusshield.space
—
domainmurvpn.space
—
domainhorizonguard.space
—
domainpauktun.space
—
domainatlasvpn.space
—
domainnetroutehub.space
—
domainvpnfasters.space
—
domainrouteshield.space
—
domaingusenvpn.online
—
domainspidervpn.online
—
domainmyxavpn.pro
—
domaingetmyxa.com
—
domainmyxavpn.com
—
domainmyxavpn.online
—
domainmyxavpn.tech
—
domainmyxasafe.space
—
domaincipherway.space
—
domaingusentun.space
—
domaininternetprvpn.ru
—
domainkorovkavpn.space
—
domainmyxavpn.space
—
domainosavpn.su
—
domainsalega.ru
—
domainshershvpn.space
—
domainstableproxy.space
—
domaintarakanvpn.online
—
domaintunnelbase.space
—
domainusachvpn.su
—
domainvpnkomar.space
—
domainvpnmyha.shop
—
domainvpnmyxa.site
—
domainzhuknet.online
—
domainzhukvpn.online
—
domainjustifications.md
—
domainau.stealthpath.space
—
domainde.stealthpath.space
—
domainfr.stealthpath.space
—
domaingb.stealthpath.space
—
domaingit.myxavpn.com
—
domainjp.stealthpath.space
—
domainmonitoring.myxavpn.com
—
domainnl.stealthpath.space
—
domainsg.stealthpath.space
—
domainsub.myxasecure.space
—
domaintr.stealthpath.space
—
domainus.stealthpath.space
—
domainxray.myxavpn.com
—

Hash

ValueDescriptionCopy
hash1dea4975f7aaba71bf7821fcf62deca470ef5e21f45c947b103ddeb836ef9b81
—

Url

ValueDescriptionCopy
urlhttp://myxavpn.pro/oferta/
—

Threat ID: 6a7c2730bf8831d53933836a

Added to database: 08/12/2026, 07:56:32 UTC

Last enriched: 08/12/2026, 09:33:53 UTC

Last updated: 09/24/2026, 15:07:07 UTC

Views: 206

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses