Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

0
Medium
Published: 08/12/2026 (08/12/2026, 06:52:44 UTC)
Source: AlienVault OTX General

Description

Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 09:33:53 UTC

Technical Analysis

Socket's Threat Research Team discovered a coordinated campaign of 737 malicious Chrome VPN and proxy extensions distributed across 40 developer accounts. These extensions impersonate 66 established VPN brands, including Proton VPN, NordVPN, and AmneziaVPN, accumulating over 75,000 installs. They route all browser traffic through SOCKS5 proxies on port 1082 controlled by a single operator, placing the attacker in an adversary-in-the-middle position. Premium tiers advertise non-functional servers in five countries. The campaign employs DNS-over-HTTPS for evasion, substitutes malicious code after extension approval, and manipulates Chrome Web Store reviews to appear legitimate. The operation is linked to a Russian subscription VPN business with a tax-registered individual as the contracting party.

Potential Impact

Users installing these malicious extensions risk having all their browser traffic intercepted and redirected through attacker-controlled proxies, enabling potential data interception and manipulation. Brand impersonation may lead to user trust and increased installation rates. The use of evasion techniques complicates detection and removal. Premium features advertised are non-functional, indicating fraud. The campaign targets Russian-speaking users seeking to bypass regional restrictions.

Defensive Guidance

No official patch or remediation is applicable as this is a malicious campaign involving third-party Chrome extensions. Users should avoid installing VPN or proxy extensions from unverified sources and verify the legitimacy of extensions by checking developer accounts and user reviews carefully. Security teams should monitor for and block these malicious extensions where possible. Google Chrome Web Store users should report suspicious extensions to Google for removal. Vendors and platform operators should continue to improve detection and review processes to prevent similar campaigns.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://socket.dev/blog/chrome-vpn-extension-impersonation"]
Adversary
null
Pulse Id
6a7c183cfe509b035144c5a6
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip185.252.215.98
ip80.92.204.33
ip94.131.118.237
ip80.92.204.47
ip86.104.74.110
ip94.131.118.39
ip178.130.47.44
ip178.130.47.129
ip103.35.191.173
ip194.150.220.163
ip147.45.60.241
ip103.35.189.225
ip5.180.30.122
ip45.89.110.227
ip80.92.206.84
ip185.252.215.97
ip5.180.30.15
ip212.192.14.75
ip130.17.1.19
ip138.124.244.206
ip78.153.155.112
ip81.90.31.73

Domain

ValueDescriptionCopy
domainvpn-myxa.ru
domainsverchtun.store
domainmyxavpn.site
domainvaultvpn.space
domainsilashield.space
domainshieldtunnel.space
domainturbotunnel.space
domainechosecure.space
domainbezopasnet.space
domainzenshield.space
domainskyproxy.space
domainroutekeeper.space
domainstealthpath.space
domainsecurepulse.space
domainironproxy.space
domainprimeproxy.space
domainmaskirovka.space
domainskorostvpn.space
domaincloudmask.space
domainsverchvpn.space
domainnimbusshield.space
domainmurvpn.space
domainhorizonguard.space
domainpauktun.space
domainatlasvpn.space
domainnetroutehub.space
domainvpnfasters.space
domainrouteshield.space
domaingusenvpn.online
domainspidervpn.online
domainmyxavpn.pro
domaingetmyxa.com
domainmyxavpn.com
domainmyxavpn.online
domainmyxavpn.tech
domainmyxasafe.space
domaincipherway.space
domaingusentun.space
domaininternetprvpn.ru
domainkorovkavpn.space
domainmyxavpn.space
domainosavpn.su
domainsalega.ru
domainshershvpn.space
domainstableproxy.space
domaintarakanvpn.online
domaintunnelbase.space
domainusachvpn.su
domainvpnkomar.space
domainvpnmyha.shop
domainvpnmyxa.site
domainzhuknet.online
domainzhukvpn.online
domainjustifications.md
domainau.stealthpath.space
domainde.stealthpath.space
domainfr.stealthpath.space
domaingb.stealthpath.space
domaingit.myxavpn.com
domainjp.stealthpath.space
domainmonitoring.myxavpn.com
domainnl.stealthpath.space
domainsg.stealthpath.space
domainsub.myxasecure.space
domaintr.stealthpath.space
domainus.stealthpath.space
domainxray.myxavpn.com

Hash

ValueDescriptionCopy
hash1dea4975f7aaba71bf7821fcf62deca470ef5e21f45c947b103ddeb836ef9b81

Url

ValueDescriptionCopy
urlhttp://myxavpn.pro/oferta/

Threat ID: 6a7c2730bf8831d53933836a

Added to database: 08/12/2026, 07:56:32 UTC

Last enriched: 08/12/2026, 09:33:53 UTC

Last updated: 08/12/2026, 19:20:27 UTC

Views: 14

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses