Security researchers at Socket have uncovered a large impersonation and browser traffic redirection campaign in the Chrome Web Store.
According to a news post on the official website, the campaign uploaded 737 VPN extensions to the Chrome Web Store and managed to lure more than 75,000 users to installing them on their devices.
The extensions impersonated 66 legitimate privacy and VPN brands—such as NordVPN, Proton VPN, and Surfshark—to deceive users into downloading them.
Core Threat Behaviors
- Traffic Interception: Once activated, the extensions route the victim’s entire browser session through a SOCKS5 proxy controlled by a single threat actor. This places the attacker in a position to read and monitor all browser traffic.
- Subscription Fraud: The extensions funnel users toward a paid subscription tier that promises premium server locations (such as Japan, Canada, and Australia). However, Socket found that none of these premium servers actually exist.
Deceptive Tactics & Evasion
- DNS-over-HTTPS Evasion: The extensions use Cloudflare and Google’s DNS-over-HTTPS to silently resolve proxy IPs, preventing the victim’s machine from emitting plaintext DNS queries that security software might flag.
- Store Review Gaming: The developers submitted false justifications to Chrome Web Store reviewers and used post-approval code substitution to sneak in the malicious proxy behaviors.
- Hidden Domains: An internal developer manual accidentally left inside one of the extensions revealed explicit instructions to staff to never hardcode the actual domains into the extension, ensuring they stay hidden from automated scanners.
The campaign specifically targets Russian-speaking users who are trying to bypass internet censorship to access blocked services like YouTube, Instagram, and ChatGPT. By impersonating trusted anti-censorship tools, the attackers successfully tricked thousands of users into handing over full visibility of their web browsing activity to a threat actor based in Russia.












