Hundreds of Fake Chrome VPNs Hijack Browsing

The Hacker News · Medium sophistication
Last updated August 12, 2026

Researchers found 737 Chrome VPN/proxy extensions that impersonated well-known privacy brands and routed users’ browser traffic through attacker-controlled SOCKS5 proxies. The activity mainly targeted Russian-speaking users trying to access blocked services, putting the operator in a position to observe browsing destinations and other metadata. Google removed some extensions, but many were still active at the time of reporting.

Key findings

  • 737 free VPN/proxy extensions were found “mainly target[ing] Russian-speaking users seeking access to blocked services.”
  • 274 extensions “impersonate 66 established VPN and privacy brands,” including Proton VPN, NordVPN, Surfshark, and others.
  • Researchers observed that “520 of the 522 in the bulk corpus route browser traffic through the same SOCKS5 infrastructure.”
  • Extensions set Chrome proxy settings to “a fixed SOCKS5 server on port 1082,” placing the operator in an adversary-in-the-middle position.
  • Some extensions used fake UX and store-review deception, including identical claims like “No data transmitted to external servers” and “No user tracking or logging.”
  • 221 extensions were removed, while “the remaining 516 extensions have been listed as active.”

Who’s being targeted

  • Commonly targeted roles: All employees, IT / Helpdesk, Security awareness, Procurement / IT asset management (software approvals), Browser management / Endpoint management teams.
  • Affected industries: Any organization with Chrome users, Consumer internet users, Media and information access users in censored regions.
  • Attack channels: website.
  • Impersonated: Well-known VPN/privacy brands (e.g., Proton VPN, NordVPN, Surfshark), A VPN/proxy extension posing as a legitimate privacy tool.

Awareness takeaways

  • Only install browser extensions from verified publishers, and treat brand look-alikes as suspicious.
  • Be cautious of ‘free VPN’ tools: they can route all browsing through third-party infrastructure that can observe where you’re going online.
  • Watch for product claims that don’t match reality (fake premium tiers/locations or fake connection indicators).
  • Assume an extension can change after approval; updates can introduce new behavior, so monitor and re-review extensions over time.

Red flags to watch for

  • Impersonates a known brand rather than being published by the official vendor
  • Promises paid tiers or premium locations that do not exist
  • Routes all traffic through a fixed proxy (not a transparent, vendor-managed VPN)
  • Fake or misleading interface/connection status
  • Only bypasses localhost/127.0.0.1 while funneling everything else through a proxy
  • Adds new remote configuration after approval (behavior changes over time)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

That “free Chrome VPN” you just installed? It might be sending every site you visit through someone else’s server. Researchers found 737 Chrome VPN and proxy extensions, many in Russian, impersonating brands like Proton VPN, NordVPN, and Surfshark. Behind the scenes they set Chrome to use a fixed SOCKS5 proxy on port 1082, so one provider sits in the middle of your entire browser session. The trick: a slick fake interface. The extension shows a nice connect animation and status “Connected”, but tests show every VPN connection fails while your real browsing still goes through their proxy. Many even promise fake premium locations that don’t exist. Your move: if you use a VPN in Chrome, open the extension’s page and check the publisher. If it’s not the official vendor, remove it now, don’t let a fake VPN sit in the middle of your browsing.

Similar attacks

Fake IRS Letters and BoA Emails Push Remote Access Scams

Fake IRS Letters and BoA Emails Push Remote Access Scams

This weekly roundup includes real-world social engineering campaigns, including scammers mailing fake IRS letters to cryptocurrency holders and a phishing campaign impersonating Bank of America. The lures are designed to pressure victims into visiting a bogus compliance portal or installing remote…

August 9, 2026
Hotel Wi‑Fi DNS Hijack Steals M365 Logins

Hotel Wi‑Fi DNS Hijack Steals M365 Logins

Researchers report attackers compromising hotel and venue Wi‑Fi “captive portal” gateways to redirect Microsoft 365 sign-ins to attacker-controlled lookalike domains. Victims can have their Microsoft 365 credentials stolen without clicking a phishing link or installing malware, because the…

July 28, 2026
Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Microsoft says a Russian-linked group is abusing hotel and conference Wi‑Fi “captive portals” to trick travelers into entering corporate credentials or installing malware. Victims see what looks like a normal Wi‑Fi login flow, but attackers manipulate DNS/website traffic to redirect them to fake…

August 4, 2026
Fake GitHub AI Repos Trick Devs Into Malware

Fake GitHub AI Repos Trick Devs Into Malware

Researchers say criminals are cloning popular GitHub repositories for AI tools and developer resources, then quietly changing installation instructions to deliver an infostealer. The pages look legitimate (including original contributors), which lures developers into downloading and running a ZIP…

August 4, 2026
Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Researchers described an active phishing campaign that tricks people with fake Adobe/Zoom update and “document review” themes to install the legitimate ScreenConnect remote-access tool. Once installed, attackers get persistent remote control of the victim’s computer while blending in as normal IT…

August 4, 2026
ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026