Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hundreds of Fake VPN Extensions Divert Browser Traffic

Hundreds of Fake VPN Extensions Divert Browser Traffic

Posted on August 13, 2026 By CWS

Researchers have uncovered a vast network of Chrome extensions claiming to provide VPN or proxy services but actually redirecting browser traffic through SOCKS5 proxies under the control of a potentially malicious operation. The extensions, numbering 737, were distributed through more than 40 Chrome Web Store developer accounts, amassing over 75,000 installations. This discovery highlights the widespread nature of the threat, particularly targeting Russian-speaking users seeking unrestricted internet access.

Scope and Impact of the Malicious Extensions

Security analysts at Socket.dev identified this campaign by scrutinizing numerous extension packages and store listings. They reported that 274 of these extensions mimicked well-known VPN and privacy brands to appear legitimate. Although the study did not assert that all data was intercepted or misused, it confirmed that the infrastructure allowed operators to monitor browser traffic while the extensions were active.

The core functionality of these extensions was straightforward yet broad in its impact. Out of 522 analyzed packages, 520 configured Chrome to route traffic through a SOCKS5 server on port 1082, sparing only local addresses. Consequently, all browser activity was funneled through this relay when users activated the extension. This setup exposed users’ destination visits, connection metadata, and source IP addresses to the proxy operators, and unsecured HTTP requests could potentially reveal the full content of these communications.

Deceptive Practices and User Risks

The extensions, which primarily required proxy permissions, might seem harmless to casual users. However, these permissions enabled the extensions to dictate the destination of browser traffic. In 104 instances, the extensions used encrypted DNS services to resolve proxy hosts, obscuring the typical domain lookup process for Chrome.

Socket.dev’s findings revealed that 66 extensions utilized remote configurations, allowing them to modify settings without user consent or extension updates. This capability, previously seen in other surveillance campaigns, underscores the risk posed by even approved extensions that can later alter their threat profile.

Despite store descriptions promising secure connections, users were essentially handing over control to unknown third-party operations. This discrepancy between advertised capabilities and actual functionality is the central hazard of the campaign, facilitating potential user profiling and surveillance.

Protective Measures and Ongoing Threat

The proxy settings alone do not inherently indicate malicious intent since many privacy tools require traffic routing capabilities. However, the evidence of brand impersonation, unfulfilled promises of premium features, misleading reviews, and post-approval functionality changes collectively suggest a coordinated malicious effort.

Investigations revealed that some extensions promoted premium servers which did not exist, while others were designed to fail connection attempts deliberately. Furthermore, despite Google removing 221 of these extensions, 516 remain active, highlighting the resilience and persistence of such malicious campaigns.

To mitigate these threats, users who suspect they have installed one of these extensions should uninstall it, scrutinize their Chrome proxy settings, and change any credentials entered on non-HTTPS sites during its active period. Organizations are advised to audit extensions with proxy access, monitor changes in proxy settings, and implement domain and address blocklists at both DNS and network egress levels, as encrypted DNS can circumvent DNS-only controls. Regular evaluations of extension permissions can help detect similar threats before they proliferate.

Cyber Security News Tags:browser traffic, Chrome extensions, Chrome Web Store, Cybersecurity, extension security, fake extensions, internet privacy, malicious software, Malware, online safety, Phishing, proxy settings, SOCKS5 proxy, threat intelligence, VPN security

Post navigation

Previous Post: Critical VMware vCenter Vulnerability Exploited by Hackers
Next Post: WordPress Urges Update to Fix Critical RCE Vulnerability

Related Posts

Identity Theft Surges as Criminals Deploy Advanced Tactics to Steal Personal Data Identity Theft Surges as Criminals Deploy Advanced Tactics to Steal Personal Data Cyber Security News
Iranian APTs Hackers Actively Attacking Transportation and Manufacturing Sectors Iranian APTs Hackers Actively Attacking Transportation and Manufacturing Sectors Cyber Security News
New Inboxfuscation Tool That Bypasses Microsoft Exchange Inbox Rules and Evade Detection New Inboxfuscation Tool That Bypasses Microsoft Exchange Inbox Rules and Evade Detection Cyber Security News
GitHub Copilot and Visual Studio Vulnerabilities Allow Attacker to Bypass Security Feature GitHub Copilot and Visual Studio Vulnerabilities Allow Attacker to Bypass Security Feature Cyber Security News
WD Discovery Desktop App for Windows Vulnerability Enables Arbitrary Code Execution WD Discovery Desktop App for Windows Vulnerability Enables Arbitrary Code Execution Cyber Security News
GitLab SSRF Vulnerability Exploited: CISA Issues Warning GitLab SSRF Vulnerability Exploited: CISA Issues Warning Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Unpatched Citrix NetScaler Flaws Pose Security Threat
  • Citrix Faces Critical NetScaler RCE Vulnerabilities
  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Unpatched Citrix NetScaler Flaws Pose Security Threat
  • Citrix Faces Critical NetScaler RCE Vulnerabilities
  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark