737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.
AI Analysis
Technical Summary
Socket's Threat Research Team discovered a coordinated campaign of 737 malicious Chrome VPN and proxy extensions distributed across 40 developer accounts. These extensions impersonate 66 established VPN brands, including Proton VPN, NordVPN, and AmneziaVPN, accumulating over 75,000 installs. They route all browser traffic through SOCKS5 proxies on port 1082 controlled by a single operator, placing the attacker in an adversary-in-the-middle position. Premium tiers advertise non-functional servers in five countries. The campaign employs DNS-over-HTTPS for evasion, substitutes malicious code after extension approval, and manipulates Chrome Web Store reviews to appear legitimate. The operation is linked to a Russian subscription VPN business with a tax-registered individual as the contracting party.
Potential Impact
Users installing these malicious extensions risk having all their browser traffic intercepted and redirected through attacker-controlled proxies, enabling potential data interception and manipulation. Brand impersonation may lead to user trust and increased installation rates. The use of evasion techniques complicates detection and removal. Premium features advertised are non-functional, indicating fraud. The campaign targets Russian-speaking users seeking to bypass regional restrictions.
Mitigation Recommendations
No official patch or remediation is applicable as this is a malicious campaign involving third-party Chrome extensions. Users should avoid installing VPN or proxy extensions from unverified sources and verify the legitimacy of extensions by checking developer accounts and user reviews carefully. Security teams should monitor for and block these malicious extensions where possible. Google Chrome Web Store users should report suspicious extensions to Google for removal. Vendors and platform operators should continue to improve detection and review processes to prevent similar campaigns.
Indicators of Compromise
- ip: 185.252.215.98
- ip: 80.92.204.33
- ip: 94.131.118.237
- ip: 80.92.204.47
- ip: 86.104.74.110
- ip: 94.131.118.39
- ip: 178.130.47.44
- ip: 178.130.47.129
- domain: vpn-myxa.ru
- ip: 103.35.191.173
- ip: 194.150.220.163
- domain: sverchtun.store
- domain: myxavpn.site
- ip: 147.45.60.241
- domain: vaultvpn.space
- domain: silashield.space
- domain: shieldtunnel.space
- domain: turbotunnel.space
- domain: echosecure.space
- domain: bezopasnet.space
- domain: zenshield.space
- domain: skyproxy.space
- domain: routekeeper.space
- domain: stealthpath.space
- domain: securepulse.space
- domain: ironproxy.space
- domain: primeproxy.space
- domain: maskirovka.space
- domain: skorostvpn.space
- domain: cloudmask.space
- domain: sverchvpn.space
- domain: nimbusshield.space
- domain: murvpn.space
- domain: horizonguard.space
- domain: pauktun.space
- domain: atlasvpn.space
- domain: netroutehub.space
- domain: vpnfasters.space
- domain: routeshield.space
- domain: gusenvpn.online
- domain: spidervpn.online
- ip: 103.35.189.225
- ip: 5.180.30.122
- ip: 45.89.110.227
- ip: 80.92.206.84
- ip: 185.252.215.97
- ip: 5.180.30.15
- ip: 212.192.14.75
- domain: myxavpn.pro
- domain: getmyxa.com
- domain: myxavpn.com
- domain: myxavpn.online
- domain: myxavpn.tech
- domain: myxasafe.space
- domain: cipherway.space
- domain: gusentun.space
- domain: internetprvpn.ru
- domain: korovkavpn.space
- domain: myxavpn.space
- domain: osavpn.su
- domain: salega.ru
- domain: shershvpn.space
- domain: stableproxy.space
- domain: tarakanvpn.online
- domain: tunnelbase.space
- domain: usachvpn.su
- domain: vpnkomar.space
- domain: vpnmyha.shop
- domain: vpnmyxa.site
- domain: zhuknet.online
- domain: zhukvpn.online
- hash: 1dea4975f7aaba71bf7821fcf62deca470ef5e21f45c947b103ddeb836ef9b81
- ip: 130.17.1.19
- ip: 138.124.244.206
- ip: 78.153.155.112
- ip: 81.90.31.73
- url: http://myxavpn.pro/oferta/
- domain: justifications.md
- domain: au.stealthpath.space
- domain: de.stealthpath.space
- domain: fr.stealthpath.space
- domain: gb.stealthpath.space
- domain: git.myxavpn.com
- domain: jp.stealthpath.space
- domain: monitoring.myxavpn.com
- domain: nl.stealthpath.space
- domain: sg.stealthpath.space
- domain: sub.myxasecure.space
- domain: tr.stealthpath.space
- domain: us.stealthpath.space
- domain: xray.myxavpn.com
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
Description
Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Socket's Threat Research Team discovered a coordinated campaign of 737 malicious Chrome VPN and proxy extensions distributed across 40 developer accounts. These extensions impersonate 66 established VPN brands, including Proton VPN, NordVPN, and AmneziaVPN, accumulating over 75,000 installs. They route all browser traffic through SOCKS5 proxies on port 1082 controlled by a single operator, placing the attacker in an adversary-in-the-middle position. Premium tiers advertise non-functional servers in five countries. The campaign employs DNS-over-HTTPS for evasion, substitutes malicious code after extension approval, and manipulates Chrome Web Store reviews to appear legitimate. The operation is linked to a Russian subscription VPN business with a tax-registered individual as the contracting party.
Potential Impact
Users installing these malicious extensions risk having all their browser traffic intercepted and redirected through attacker-controlled proxies, enabling potential data interception and manipulation. Brand impersonation may lead to user trust and increased installation rates. The use of evasion techniques complicates detection and removal. Premium features advertised are non-functional, indicating fraud. The campaign targets Russian-speaking users seeking to bypass regional restrictions.
Defensive Guidance
No official patch or remediation is applicable as this is a malicious campaign involving third-party Chrome extensions. Users should avoid installing VPN or proxy extensions from unverified sources and verify the legitimacy of extensions by checking developer accounts and user reviews carefully. Security teams should monitor for and block these malicious extensions where possible. Google Chrome Web Store users should report suspicious extensions to Google for removal. Vendors and platform operators should continue to improve detection and review processes to prevent similar campaigns.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://socket.dev/blog/chrome-vpn-extension-impersonation"]
- Adversary
- null
- Pulse Id
- 6a7c183cfe509b035144c5a6
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip185.252.215.98 | — | |
ip80.92.204.33 | — | |
ip94.131.118.237 | — | |
ip80.92.204.47 | — | |
ip86.104.74.110 | — | |
ip94.131.118.39 | — | |
ip178.130.47.44 | — | |
ip178.130.47.129 | — | |
ip103.35.191.173 | — | |
ip194.150.220.163 | — | |
ip147.45.60.241 | — | |
ip103.35.189.225 | — | |
ip5.180.30.122 | — | |
ip45.89.110.227 | — | |
ip80.92.206.84 | — | |
ip185.252.215.97 | — | |
ip5.180.30.15 | — | |
ip212.192.14.75 | — | |
ip130.17.1.19 | — | |
ip138.124.244.206 | — | |
ip78.153.155.112 | — | |
ip81.90.31.73 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainvpn-myxa.ru | — | |
domainsverchtun.store | — | |
domainmyxavpn.site | — | |
domainvaultvpn.space | — | |
domainsilashield.space | — | |
domainshieldtunnel.space | — | |
domainturbotunnel.space | — | |
domainechosecure.space | — | |
domainbezopasnet.space | — | |
domainzenshield.space | — | |
domainskyproxy.space | — | |
domainroutekeeper.space | — | |
domainstealthpath.space | — | |
domainsecurepulse.space | — | |
domainironproxy.space | — | |
domainprimeproxy.space | — | |
domainmaskirovka.space | — | |
domainskorostvpn.space | — | |
domaincloudmask.space | — | |
domainsverchvpn.space | — | |
domainnimbusshield.space | — | |
domainmurvpn.space | — | |
domainhorizonguard.space | — | |
domainpauktun.space | — | |
domainatlasvpn.space | — | |
domainnetroutehub.space | — | |
domainvpnfasters.space | — | |
domainrouteshield.space | — | |
domaingusenvpn.online | — | |
domainspidervpn.online | — | |
domainmyxavpn.pro | — | |
domaingetmyxa.com | — | |
domainmyxavpn.com | — | |
domainmyxavpn.online | — | |
domainmyxavpn.tech | — | |
domainmyxasafe.space | — | |
domaincipherway.space | — | |
domaingusentun.space | — | |
domaininternetprvpn.ru | — | |
domainkorovkavpn.space | — | |
domainmyxavpn.space | — | |
domainosavpn.su | — | |
domainsalega.ru | — | |
domainshershvpn.space | — | |
domainstableproxy.space | — | |
domaintarakanvpn.online | — | |
domaintunnelbase.space | — | |
domainusachvpn.su | — | |
domainvpnkomar.space | — | |
domainvpnmyha.shop | — | |
domainvpnmyxa.site | — | |
domainzhuknet.online | — | |
domainzhukvpn.online | — | |
domainjustifications.md | — | |
domainau.stealthpath.space | — | |
domainde.stealthpath.space | — | |
domainfr.stealthpath.space | — | |
domaingb.stealthpath.space | — | |
domaingit.myxavpn.com | — | |
domainjp.stealthpath.space | — | |
domainmonitoring.myxavpn.com | — | |
domainnl.stealthpath.space | — | |
domainsg.stealthpath.space | — | |
domainsub.myxasecure.space | — | |
domaintr.stealthpath.space | — | |
domainus.stealthpath.space | — | |
domainxray.myxavpn.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash1dea4975f7aaba71bf7821fcf62deca470ef5e21f45c947b103ddeb836ef9b81 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://myxavpn.pro/oferta/ | — |
Threat ID: 6a7c2730bf8831d53933836a
Added to database: 08/12/2026, 07:56:32 UTC
Last enriched: 08/12/2026, 09:33:53 UTC
Last updated: 08/12/2026, 19:20:27 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.