Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hundreds of Fake VPN Extensions Divert Browser Traffic

Hundreds of Fake VPN Extensions Divert Browser Traffic

Posted on August 13, 2026 By CWS

Researchers have uncovered a vast network of Chrome extensions claiming to provide VPN or proxy services but actually redirecting browser traffic through SOCKS5 proxies under the control of a potentially malicious operation. The extensions, numbering 737, were distributed through more than 40 Chrome Web Store developer accounts, amassing over 75,000 installations. This discovery highlights the widespread nature of the threat, particularly targeting Russian-speaking users seeking unrestricted internet access.

Scope and Impact of the Malicious Extensions

Security analysts at Socket.dev identified this campaign by scrutinizing numerous extension packages and store listings. They reported that 274 of these extensions mimicked well-known VPN and privacy brands to appear legitimate. Although the study did not assert that all data was intercepted or misused, it confirmed that the infrastructure allowed operators to monitor browser traffic while the extensions were active.

The core functionality of these extensions was straightforward yet broad in its impact. Out of 522 analyzed packages, 520 configured Chrome to route traffic through a SOCKS5 server on port 1082, sparing only local addresses. Consequently, all browser activity was funneled through this relay when users activated the extension. This setup exposed users’ destination visits, connection metadata, and source IP addresses to the proxy operators, and unsecured HTTP requests could potentially reveal the full content of these communications.

Deceptive Practices and User Risks

The extensions, which primarily required proxy permissions, might seem harmless to casual users. However, these permissions enabled the extensions to dictate the destination of browser traffic. In 104 instances, the extensions used encrypted DNS services to resolve proxy hosts, obscuring the typical domain lookup process for Chrome.

Socket.dev’s findings revealed that 66 extensions utilized remote configurations, allowing them to modify settings without user consent or extension updates. This capability, previously seen in other surveillance campaigns, underscores the risk posed by even approved extensions that can later alter their threat profile.

Despite store descriptions promising secure connections, users were essentially handing over control to unknown third-party operations. This discrepancy between advertised capabilities and actual functionality is the central hazard of the campaign, facilitating potential user profiling and surveillance.

Protective Measures and Ongoing Threat

The proxy settings alone do not inherently indicate malicious intent since many privacy tools require traffic routing capabilities. However, the evidence of brand impersonation, unfulfilled promises of premium features, misleading reviews, and post-approval functionality changes collectively suggest a coordinated malicious effort.

Investigations revealed that some extensions promoted premium servers which did not exist, while others were designed to fail connection attempts deliberately. Furthermore, despite Google removing 221 of these extensions, 516 remain active, highlighting the resilience and persistence of such malicious campaigns.

To mitigate these threats, users who suspect they have installed one of these extensions should uninstall it, scrutinize their Chrome proxy settings, and change any credentials entered on non-HTTPS sites during its active period. Organizations are advised to audit extensions with proxy access, monitor changes in proxy settings, and implement domain and address blocklists at both DNS and network egress levels, as encrypted DNS can circumvent DNS-only controls. Regular evaluations of extension permissions can help detect similar threats before they proliferate.

Cyber Security News Tags:browser traffic, Chrome extensions, Chrome Web Store, Cybersecurity, extension security, fake extensions, internet privacy, malicious software, Malware, online safety, Phishing, proxy settings, SOCKS5 proxy, threat intelligence, VPN security

Post navigation

Previous Post: Critical VMware vCenter Vulnerability Exploited by Hackers

Related Posts

FortiOS and FortiSwitchManager Vulnerability Let Remote Attackers Execute Arbitrary Code FortiOS and FortiSwitchManager Vulnerability Let Remote Attackers Execute Arbitrary Code Cyber Security News
ChatGPT Exploit Turns Web Pages Into Phishing Tools ChatGPT Exploit Turns Web Pages Into Phishing Tools Cyber Security News
Mongobleed PoC Exploit Tool Released for MongoDB Flaw that Exposes Sensitive Data Mongobleed PoC Exploit Tool Released for MongoDB Flaw that Exposes Sensitive Data Cyber Security News
Iranian Threat Actors Attacking U.S. Critical Infrastructure Including Water Systems Iranian Threat Actors Attacking U.S. Critical Infrastructure Including Water Systems Cyber Security News
Jupyter Misconfiguration Flaw Allow Attackers to Escalate Privileges as Root User Jupyter Misconfiguration Flaw Allow Attackers to Escalate Privileges as Root User Cyber Security News
Cisco Warns of Identity Services Engine RCE Vulnerability Exploited in the Wild Cisco Warns of Identity Services Engine RCE Vulnerability Exploited in the Wild Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hundreds of Fake VPN Extensions Divert Browser Traffic
  • Critical VMware vCenter Vulnerability Exploited by Hackers
  • Eclipse Ransomware Unveils Multi-Platform RaaS Targeting Diverse Systems
  • Mindgard Secures $30 Million to Enhance AI Security
  • Global Cyber Campaign Targets Salesforce and ServiceNow

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hundreds of Fake VPN Extensions Divert Browser Traffic
  • Critical VMware vCenter Vulnerability Exploited by Hackers
  • Eclipse Ransomware Unveils Multi-Platform RaaS Targeting Diverse Systems
  • Mindgard Secures $30 Million to Enhance AI Security
  • Global Cyber Campaign Targets Salesforce and ServiceNow

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark