Security researchers at Socket have uncovered a large impersonation and browser traffic redirection campaign in the Chrome Web Store.
According to a news post on the official website, the campaign uploaded 737 VPN extensions to the Chrome Web Store and managed to lure more than 75,000 users to installing them on their devices.
The extensions impersonated 66 legitimate privacy and VPN brands—such as NordVPN, Proton VPN, and Surfshark—to deceive users into downloading them.
Core Threat Behaviors
- Traffic Interception: Once activated, the extensions route the victim’s entire browser session through a SOCKS5 proxy controlled by a single threat actor. This places the attacker in a position to read and monitor all browser traffic.
- Subscription Fraud: The extensions funnel users toward a paid subscription tier that promises premium server locations (such as Japan, Canada, and Australia). However, Socket found that none of these premium servers actually exist.
Deceptive Tactics & Evasion
- DNS-over-HTTPS Evasion: The extensions use Cloudflare and Google’s DNS-over-HTTPS to silently resolve proxy IPs, preventing the victim’s machine from emitting plaintext DNS queries that security software might flag.
- Store Review Gaming: The developers submitted false justifications to Chrome Web Store reviewers and used post-approval code substitution to sneak in the malicious proxy behaviors.
- Hidden Domains: An internal developer manual accidentally left inside one of the extensions revealed explicit instructions to staff to never hardcode the actual domains into the extension, ensuring they stay hidden from automated scanners.
The campaign specifically targets Russian-speaking users who are trying to bypass internet censorship to access blocked services like YouTube, Instagram, and ChatGPT. By impersonating trusted anti-censorship tools, the attackers successfully tricked thousands of users into handing over full visibility of their web browsing activity to a threat actor based in Russia.

May be better off using UltraSurf or Privoxy; Privado works reasonably well for BBC.
I’m shocked. SHOCKED I tell you! Would never have expected such behavior from Google.
Google starts enforcing its new developer verification system in Brazil, Indonesia, Singapore, and Thailand on certified Android devices sometime in mid-September 2026 and moves on to other locations from there.
Here, we have the motivation and reason behind why there are so many attempts at usurping the vpn addresses. Russians, got it, they want their full, unrestricted internet back but how does this fare for the security of this distribution system overall?
Yeah? So? What does this have to do with Chrome extensions bruh? Currently, nothing! Thinking that if the trusted verification works well in Android, will it then spread to the rest of the google empire?
Its a highly controversial move and an entire article can be written on the side-loading of non-playstore app downloads on its own. However, what if the enforcement of developer verification is successful?
Guess we’ll see, after the results with android.
GAFAM, and the beat goes on. When it’s not one of them, it’s another. The whole pack is a nuisance. Microsoft at its beginnings was not, but that’s history by now. Find alternatives, they exist. Get up and fight, by dignity, for your privacy, mental health when invaded by ads and trackers which are for the most part initiated, induced by GAFAM. REACT!