Skip to main content

Threats Tagged 'vpn impersonation'

View all threats tagged with 'vpn impersonation'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: vpn impersonation

Threats Tagged 'vpn impersonation'

Click on any threat for detailed analysis and mitigation recommendations

A cluster of 31 Russian-language Chrome extensions masquerading as VPN services for blocked platforms like RuTracker, YouTube, Telegram, Instagram, ChatGPT, and Netflix shares a single malicious codebase. Published from three linked Google accounts, these extensions collectively affect approximately 356,000 users, with the flagship RuTracker VPN extension holding 200,000 installations. The extensions request extensive proxy permissions and dynamically fetch proxy server configurations from remote sources including GitHub Pages, Blogspot, Google Docs, and Telegram channels after installation. This architecture allows operators to modify traffic routing without pushing updates. The configuration uses obfuscated server lists with shared credentials and offers a paid VIP tier for 299 roubles. Some proxy hostnames match those used by Browsec VPN premium servers, suggesting a potential operational connection.

Join the discussion

Malicious browser extensions distributed through Chrome Web Store and Firefox Add-ons marketplaces posed as free VPN services while secretly stealing clipboard data. The Chrome extension, with 146 users, and Firefox extension, with 3,499 users, initially functioned as proxy tools but later incorporated clipboard theft through staged updates. Chrome versions 1.1 onwards and Firefox version 1.3.3 onwards continuously monitored clipboard contents every 500-1500 milliseconds, capturing passwords, API keys, cryptocurrency addresses, and authentication tokens. Stolen data was chunked, tagged with session identifiers, and exfiltrated via HTTP to attacker-controlled infrastructure at multiple IP addresses. Both extensions shared code patterns, infrastructure, and exfiltration endpoints despite appearing as separate products, indicating coordinated malicious operations behind legitimate-appearing privacy tools.

Join the discussion

A campaign targeting the Google Chrome Web Store has deployed over 100 malicious browser extensions masquerading as legitimate tools like VPNs, AI assistants, and crypto utilities. These extensions, while offering some promised functionality, secretly connect to threat actor infrastructure to steal user information and execute remote scripts. They can modify network traffic, deliver ads, perform redirections, and act as proxies. The campaign, discovered by DomainTools researchers, involves numerous fake domains promoting these tools. The extensions request permissions that enable cookie theft, DOM-based phishing, and dynamic script injection. Risks include account hijacking, data theft, and browsing activity monitoring. Some extensions remain on the Chrome Web Store despite Google's removal efforts.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: vpn impersonation
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses